PT-2026-34635 · Froxlor · Froxlor

Offset

·

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41231

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.6
Description The DataDump.add() function constructs the export destination path using user-supplied input but fails to pass the $fixed homedir parameter to FileDir::makeCorrectDir(). This omission bypasses symlink validation. When the ExportCron process runs with root privileges, it executes chown -R on the resolved symlink target, which allows a customer to take ownership of arbitrary directories on the system.
Recommendations Update to version 2.3.6.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41231
GHSA-75H4-C557-J89R

Affected Products

Froxlor