Skip to content
CVE Alert: CVE-2024-58383 – froxlor

CVE Alert: CVE-2024-58383 – froxlor

Redpacketsecurity admin September 14, 2026

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user’s password. On systems where the parent directories are world readable (the default on Debian 12), any unprivileged local user able to execute commands or code on the host — including virtual users without SSH access who can upload PHP/CGI scripts — can read the file and obtain the Froxlor database credentials. Database access can then be leveraged to alter an administrator’s password hash and TOTP seed, log in as a Froxlor administrator, and ultimately gain root privileges. Only instances configured to use pure-ftpd are affected.

High risk on hosts using the affected FTP integration, but immediate exploitation urgency cannot be confirmed because KEV status, SSVC exploitation state and EPSS are not provided.

A low-privilege local foothold can expose database credentials, enabling administrative account takeover and possible escalation to full host control. This is particularly serious on shared hosting platforms, where one compromised tenant or uploaded script could become a stepping stone to compromise of the control panel and other hosted services.

### Most likely attack path

The attack requires local access or code execution, but has low complexity, needs limited privileges, requires no user interaction and is not dependent on special attack conditions. An attacker would read the world-accessible credential file, authenticate to the application database, modify administrator authentication data, and use the panel’s privileged functions to pursue root-level execution. Scope is assessed as unchanged, so direct cross-host impact is not implied, although shared infrastructure may enable subsequent lateral movement.

### Who is most exposed

Multi-tenant Debian-based hosting servers running Froxlor with pure-ftpd enabled are the primary concern, especially where customers can upload PHP or CGI content. Single-tenant systems remain exposed if untrusted local users or web-service processes can execute code.

Alert on reads of the FTP database configuration by web, CGI or tenant processes.

Review database authentication and administrator credential changes.

Hunt for unexpected panel logins followed by configuration or account modifications.

Check file permissions and integrity on generated FTP configuration files.

### Mitigation and prioritisation

Apply the vendor’s fixed release promptly; treat as high-priority remediation.

If KEV is true or EPSS is at least 0.5, treat as priority 1.

Restrict file and parent-directory permissions immediately, then regenerate affected configuration.

Disable pure-ftpd integration where unused and rotate exposed database and panel credentials.

Test tenant uploads and service restarts in change control, as configuration regeneration may reintroduce unsafe permissions.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.