{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/froxlor--2.3.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-100715"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Froxlor (\u003c= 2.3.10)","Froxlor (\u003c 2.3.13)","froxlor (\u003c 2.3.12)","Froxlor (2.0.0-2.3.10)"],"_cs_severities":["critical"],"_cs_tags":["information-disclosure","api-security","credential-access","authentication-bypass","vulnerability","webserver","web-vulnerability","authorization-bypass","spoofing"],"_cs_type":"advisory","_cs_vendors":["Froxlor"],"content_html":"\u003cp\u003eFroxlor versions through 2.3.10 contain a critical vulnerability in the deleteFtpData cron task (Task 8). When an FTP account is deleted, the application queues this task to clean up associated data. The task execution flow invokes FileDir::makeCorrectDir() without the $fixed_homedir argument, causing the system to skip necessary symlink component path walking. Subsequently, the application executes a recursive 'rm -rf' operation with root privileges on the resulting path.\u003c/p\u003e\n\u003cp\u003eBecause the application appends a trailing slash to the path before execution, the underlying GNU rm utility is forced to dereference symlinks. An authenticated user with write access to their designated FTP home directory can place a symbolic link in the target path after the task is queued but before the cron job executes. This allows the attacker to redirect the recursive deletion operation to arbitrary directories on the host filesystem, resulting in cross-tenant data loss and host-level denial of service. This vulnerability is addressed in Froxlor version 2.3.12.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains authenticated access to an FTP account managed by the target Froxlor instance.\u003c/li\u003e\n\u003cli\u003eAttacker initiates the deletion of their own FTP account via the Froxlor interface, triggering the scheduling of the deleteFtpData cron task.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the target path that will be processed by the upcoming root-privileged cron cleanup job.\u003c/li\u003e\n\u003cli\u003eAttacker plants a symbolic link pointing to a critical system directory (e.g., /etc or a peer tenant's data directory) within the expected FTP home path.\u003c/li\u003e\n\u003cli\u003eThe system root user executes the scheduled cron task, which resolves the path containing the attacker-controlled symlink.\u003c/li\u003e\n\u003cli\u003eThe 'rm -rf' command dereferences the symlink and recursively deletes the contents of the target directory.\u003c/li\u003e\n\u003cli\u003eFinal impact is realized as system instability, data loss, or total host denial of service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated customer to perform arbitrary file deletion with root privileges. This can result in the destruction of cross-tenant data, the deletion of critical system configuration files, or a complete host denial of service. Given the broad permissions of the cron task, the potential for widespread data corruption is significant.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of all Froxlor installations to version 2.3.12 or later to include the patch for CVE-2026-100715. For environments that cannot be patched immediately, restrict user access to FTP home directories and audit the filesystem for unexpected symbolic links located within directories managed by Froxlor's cleanup cron tasks. Ensure that file system auditing is enabled to track 'rm' executions by the root user that target directories outside of expected user homedirs.\u003c/p\u003e\n","date_modified":"2026-09-26T16:59:28Z","date_published":"2026-09-26T14:59:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-froxlor-symlink-deletion/","summary":"Froxlor versions through 2.3.10 are vulnerable to arbitrary file deletion where authenticated users can plant symlinks to trigger recursive deletion by a root-privileged cron task, leading to potential data destruction.","title":"Arbitrary File Deletion in Froxlor via Symlink Following","url":"https://feed.craftedsignal.io/briefs/2026-09-froxlor-symlink-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Froxlor (\u003c= 2.3.10)","version":"https://jsonfeed.org/version/1.1"}