Froxlor 2.3.15 Ships as a "Bugfix" Release That Is Mostly Security Hardening
The latest drop of the open-source hosting control panel is labeled a bugfix release, but most of its substance is security work.
Floxlor released version 2.3.15 today, and the maintainers called it a bugfix update. They probably should have called it what it mostly is: a security release.
Of the thirteen changes shipped, six carry an explicit security tag. The rest tidy up stability regressions, data-loss bugs, and one nginx setting. Keep in mind that's not unusual for Froxlor this year.
The panel manages servers and the hosting resources tied to them, domains, email and FTP accounts, databases, SSH access, TLS certificates and so on. It is aimed at self-hosters, small hosting providers, and anyone who wants a web interface rather than a hand-edited config file. The project dates back to 2012, sits at nearly 1,750 GitHub stars, and is licensed under the permissive LGPL-2.1-only.
More security than the label suggests
The security half of 2.3.15 touches the places that tend to matter most in a control panel: who can authenticate, who can do what, and how far someone can reach into files they should not.
Take the change that blocks customers from adding or modifying TLS certificates on Let's Encrypt–managed domains. A rogue certificate change on an automated domain can create conflicting or orphaned state, which is annoying for you and the people who rely on your site staying up.
Then there is the one that enforces the customer_hide_options 'mysql' setting at the API layer. A hidden database server used to be re-addable through the API, even if a UI-level check caught it in the browser. Not such a great look.
The rest are similarly about boundaries. A reseller could previously fetch administrator records whose identity did not match their own via the Admins.get call. Customers could delete a parent "main" domain through a sub-domain endpoint, which risks taking down core hosting resources. And API key listing and deletion were scoped so admins and resellers can only touch keys they actually own.
That last one matters because, before this fix, the listing endpoint exposed every key on the system rather than just the ones attributable to the caller.
There is also a path-traversal tightening in the cron jobs that manage nginx fastcgi and traffic accounting. The changelog calls it closing the "remaining" symlink-containment gaps, which is a tell that earlier work in 2.3.11 was not entirely finished.
The bugfix half
The other changes are smaller but worth knowing about. SSH public keys used to vanish when FTP users shared a home directory. That data-integrity regression is now fixed, so shared-home setups stop dropping keys.
Database::showerror() threw a TypeError when it could not write the SQL-error log. It now falls back to notifying the user and syslog instead of crashing the very error path that was supposed to report the problem. That is the code path behind PR #1424.
Finally, MySQL host checks in DbManager::correctMysqlUsers() produced spurious CREATE USER errors when changing a database's access host.
There is one configuration change, too. Froxlor now sets a sensible client_max_body_size for nginx to match the configured PHP post_max_size, so mismatched request-body limits stop silently truncating or rejecting form submissions.
The full changelog runs from 2.3.14 to 2.3.15 on GitHub, as does the dedicated release page.
