Arbitrary File Deletion Vulnerability in Froxlor by Froxlor Team
CVE-2026-100715
8.5HIGH
What is CVE-2026-100715?
Froxlor versions up to 2.3.10 possess a vulnerability allowing arbitrary file deletion through symlink manipulation, particularly within the FTP data deletion cron task. When an FTP account is removed, a cron job is scheduled, which incorrectly handles directory paths by skipping necessary symlink checks. This flaw allows authenticated users to create symlinks that lead to the execution of 'rm -rf' commands with root privileges, enabling them to delete arbitrary directory trees. This poses severe risks of cross-tenant data destruction and potential denial of service on the host system. The issue has been resolved in Froxlor version 2.3.12.
Affected Version(s)
froxlor 0 < 2.3.12
froxlor 2.3.12
