PT-2026-44906 · Froxlor · Froxlor
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.7
Description
An issue exists where server-side FTP account handlers do not enforce the
system.available shells whitelist when processing add or edit requests. This allows an authenticated customer with shell delegation enabled to submit an arbitrary shell, such as /bin/bash, bypassing the restricted choices presented in the panel UI. In deployments using the default nssextrausers integration, the attacker-controlled shell is propagated into the system account database, granting real host shell access. The flaw occurs because the Ftps::add() and Ftps::update() functions perform only generic string validation instead of verifying the shell against the approved list. This can be exploited via the /customer ftp.php endpoint by manipulating the shell parameter.Recommendations
Update to version 2.3.7.
As a temporary workaround, restrict the use of the
shell parameter in the /customer ftp.php endpoint or disable customer shell delegation by setting system.allow customer shell to 0.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor