PT-2026-34635 · Froxlor · Froxlor
Published
2026-04-23
·
Updated
2026-04-23
·
CVE-2026-41231
CVSS v3.1
7.5
High
| AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Froxlor is open source server administration software. Prior to version 2.3.6,
DataDump.add() constructs the export destination path from user-supplied input without passing the $fixed homedir parameter to FileDir::makeCorrectDir(), bypassing the symlink validation that was added to all other customer-facing path operations (likely as the fix for CVE-2023-6069). When the ExportCron runs as root, it executes chown -R on the resolved symlink target, allowing a customer to take ownership of arbitrary directories on the system. Version 2.3.6 contains an updated fix.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor