PT-2026-44906 · Froxlor · Froxlor

·

CVE-2026-41235

·

Published

2026-05-29

·

Updated

2026-06-08

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.7
Description An issue exists where server-side FTP account handlers do not enforce the system.available shells whitelist when processing add or edit requests. This allows an authenticated customer with shell delegation enabled to submit an arbitrary shell, such as /bin/bash, bypassing the restricted choices presented in the panel UI. In deployments using the default nssextrausers integration, the attacker-controlled shell is propagated into the system account database, granting real host shell access. The flaw occurs because the Ftps::add() and Ftps::update() functions perform only generic string validation instead of verifying the shell against the approved list. This can be exploited via the /customer ftp.php endpoint by manipulating the shell parameter.
Recommendations Update to version 2.3.7. As a temporary workaround, restrict the use of the shell parameter in the /customer ftp.php endpoint or disable customer shell delegation by setting system.allow customer shell to 0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41235
GHSA-GCV3-5V9Q-FMHH

Affected Products

Froxlor