PT-2026-99385 · Froxlor · Froxlor
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.12
Description
Insufficient restriction and escaping of the
system.letsencryptchallengepath setting allows for command injection. The value of this setting is concatenated unescaped into the acme.sh command line within the lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php file and executed by the root cron using the FileDir::safe exec() function. Since safe exec() only blacklists specific shell metacharacters, spaces and quotes remain, allowing the value to be split into additional acme.sh arguments. An administrator or an actor with permissions to modify settings, such as through the settings-import API, can inject options like --renew-hook, --pre-hook, or --post-hook to achieve arbitrary command execution as root during the next Let's Encrypt cron run, or use --config-home and --cert-home for arbitrary file writes.Recommendations
Update to version 2.3.12 or later.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor