Executive brief
Froxlor is a web hosting control panel that manages SSL/TLS certificates via Let's Encrypt automation. An administrator or attacker with settings modification rights can inject malicious arguments into the Let's Encrypt certificate renewal command, gaining root-level code execution on the hosting panel server when the automated renewal cron job runs.
Technical details
The system.letsencryptchallengepath configuration setting is concatenated unescaped into an acme.sh command line executed by root cron via FileDir::safe_exec(). While safe_exec blacklists shell metacharacters (;|&><\$~?), it permits spaces and quotes, allowing word-splitting into arbitrary acme.sh arguments. An authenticated admin or API actor can inject options like --renew-hook, --pre-hook, --post-hook, or --config-home to achieve arbitrary command execution as root or write arbitrary files.
Affected products
- Froxlor Froxlor before 2.3.12, up to and including 2.3.10
Timeline
- 2026-09-26: disclosed: Public advisory published
- 2026-09-26: patched: Fix released in version 2.3.12