CVE-2024-58383
Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian 12), any unprivileged local user able to execute commands or code on the host — including virtual users without SSH access who can upload PHP/CGI scripts — can read the file and obtain the Froxlor database credentials. Database access can then be leveraged to alter an administrator's password hash and TOTP seed, log in as a Froxlor administrator, and ultimately gain root privileges. Only instances configured to use pure-ftpd are affected.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-732
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- froxlor froxlor
- froxlor froxlor
Weakness type
Related vulnerabilities
- CVE-2025-14988 — Incorrect Permission Assignment for Critical Resource vulnerability in iba Systems ibaPDA
- CVE-2026-21902 — Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
- CVE-2026-29188 — File Browser: TUS Delete Endpoint Bypasses Delete Permission Check
- CVE-2026-25770 — Wazuh has Privilege Escalation to Root via Cluster Protocol File Write
- CVE-2026-21765 — HCL BigFix Platform is affected by insecure permissions on private cryptographic keys
- CVE-2025-13941 — Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
- CVE-2021-47742 — Epic Games Psyonix Rocket League <=1.95 Elevation of Privileges via Insecure Permissions
- CVE-2020-36938 — WinAVR Version 20100110 - Insecure Folder Permissions