NVD CRITICAL: CVE-2026-100715 — Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink foll...
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because mak
CVE-2026-100715