Executive brief
Froxlor is a server administration panel for hosting management. A flaw in its customer data-export feature allows authenticated customers to trick the root-owned cron job into changing ownership of arbitrary system directories—such as /etc—to their user account. An attacker can gain complete control of the server and access other customers' data through this deterministic exploit that requires no race conditions.
Technical details
The vulnerability stems from two compounding defects: an off-by-one error in FileDir::makeCorrectDir() that skips symlink validation of the first path segment below the customer's home directory, and an incomplete guard in ExportCron.php that checks only the final path component with is_link(). An authenticated customer with export privileges can schedule an export to a genuine subdirectory, then replace an intermediate path component with a symlink before the root cron executes, causing chown -R to recursively transfer ownership of the linked directory tree to the customer's UID.
Affected products
- Froxlor Froxlor 2.3.10 and earlier
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: Fixed in Froxlor 2.3.12