PT-2026-99386 · Froxlor · Froxlor

·

CVE-2026-100715

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.12
Description An issue exists in the FTP data deletion cron task where the system is susceptible to arbitrary file deletion via symlink following. When an FTP account is deleted, cron task 8 (deleteFtpData) calls the makeCorrectDir() function without the $fixed homedir argument. This causes the system to skip the symlink component walk and execute rm -rf as root on the resulting path using only string-level guards. Because makeCorrectDir() appends a trailing slash, GNU rm dereferences symlinks used as intermediate or final path components. An authenticated customer with write access to the FTP home directory can create a symlink before the cron job executes, allowing the root process to recursively delete arbitrary directory trees. This can lead to cross-tenant data destruction and host denial of service.
Recommendations Update Froxlor to version 2.3.12.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100715
GHSA-PX4Q-2RF7-CVCF

Affected Products

Froxlor