PT-2026-99386 · Froxlor · Froxlor
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.12
Description
An issue exists in the FTP data deletion cron task where the system is susceptible to arbitrary file deletion via symlink following. When an FTP account is deleted, cron task 8 (deleteFtpData) calls the
makeCorrectDir() function without the $fixed homedir argument. This causes the system to skip the symlink component walk and execute rm -rf as root on the resulting path using only string-level guards. Because makeCorrectDir() appends a trailing slash, GNU rm dereferences symlinks used as intermediate or final path components. An authenticated customer with write access to the FTP home directory can create a symlink before the cron job executes, allowing the root process to recursively delete arbitrary directory trees. This can lead to cross-tenant data destruction and host denial of service.Recommendations
Update Froxlor to version 2.3.12.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor