CRLF injection in Froxlor - #VU152727
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary lines into a root-owned NSS group database.
The vulnerability exists due to improper neutralization of CRLF sequences in the additional_members parameter of the Ftps.add API when submitting a crafted additional_members value. A remote user can submit a newline-containing parameter value to inject arbitrary lines into a root-owned NSS group database.
The issue requires nssextrausers to be enabled and the FTP option to be available to customers.