Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian 12), any unprivileged local user able to execute commands or code on the host — including virtual users without SSH access who can upload PHP/CGI scripts — can read the file and obtain the Froxlor database credentials. Database access can then be leveraged to alter an administrator's password hash and TOTP seed, log in as a Froxlor administrator, and ultimately gain root privileges. Only instances configured to use pure-ftpd are affected. | |
| Title | Froxlor before 2.2.0 Insecure File Permissions mysql.conf | |
| First Time appeared |
Froxlor
Froxlor froxlor |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Froxlor
Froxlor froxlor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T12:48:23.488Z
Reserved: 2026-08-16T13:02:14.691Z
Link: CVE-2024-58383
No data.
Status : Received
Published: 2026-09-14T13:17:15.150
Modified: 2026-09-14T13:17:15.150
Link: CVE-2024-58383
No data.
OpenCVE Enrichment
No data.
-
CWE-732
Incorrect Permission Assignment for Critical Resource