PT-2026-99387 · Froxlor · Froxlor
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.12
Description
An authenticated customer with the export feature enabled can achieve host root and cross-tenant compromise. The issue occurs because the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination. Specifically, the
makeCorrectDir() function in FroxlorFileDir contains an off-by-one error during its path-component walk, skipping the first segment below the customer home directory. Additionally, the guard in ExportCron.php only checks the final component using is link(). An attacker can schedule an export to a subdirectory and replace an intermediate path component with a symlink before the root-owned cron executes. This causes the chown -R command to recursively change the ownership of the linked directory tree, such as /etc, to the customer's UID.Recommendations
Update to version 2.3.12.
Exploit
Fix
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor