Froxlor 2.3.15 Adds Six Security Fixes for API Access, Certificates, and Path Traversal

Published by

Froxlor 2.3.15 has been released as a bugfix update, but it primarily focuses on enhancing security with six of its thirteen changes addressing vulnerabilities related to authentication, API access control, and path traversal. Key fixes include preventing resellers from accessing admin records, stopping customers from deleting parent domains, and ensuring API keys are scoped to their owners only. Additionally, the update resolves smaller issues, such as preventing SSH keys from disappearing in shared FTP settings and addressing database error handling. Overall, this release reflects Froxlor's ongoing commitment to security and stability within its open-source hosting control panel



Froxlor 2.3.15 Adds Six Security Fixes for API Access, Certificates, and Path Traversal

Floxlor 2.3.15 shipped today as a bugfix release, but six of its thirteen changes are actually security fixes touching authentication, API access control, and path traversal. It closes gaps that started surfacing in 2026, including a reseller able to fetch admin records, customers deleting parent domains, and API keys exposed system-wide. The smaller bugfixes stop SSH keys from vanishing on shared FTP homes and fix a spurious database error, plus a sensible nginx body-size tweak. 

Froxlor 2.3.15 Adds Six Security Fixes for API Access, Certificates, and Path Traversal @ Linux Compatible