What potential security risks are associated with allowing users to input file names for deletion in PHP?

Allowing users to input file names for deletion in PHP can lead to security risks such as directory traversal attacks, where users can potentially delete important system files or sensitive data. To mitigate this risk, it is important to validate and sanitize user input before using it to delete files. One way to do this is by checking if the file exists in a specific directory before allowing deletion.

$directory = '/path/to/files/';
$filename = $_POST['filename'];

if (file_exists($directory . $filename)) {
    unlink($directory . $filename);
    echo 'File deleted successfully.';
} else {
    echo 'File not found.';
}