Link following in Froxlor - CVE-2026-100715
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to delete arbitrary directory trees.
The vulnerability exists due to improper link resolution before file access in the deleteFtpData cron task when processing a deletion task for an FTP account. A remote user can place a symlink in an FTP home directory to delete arbitrary directory trees.
The symlink must be planted after task creation and before cron execution.