Skip to content
Critical Vulnerability in Froxlor Exposes Database Credentials

Critical Vulnerability in Froxlor Exposes Database Credentials

First seen 14 Sep 2026, 16:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 17:19 UTC

A critical vulnerability, CVE-2024-58383, affects Froxlor versions before 2.2.0, allowing unprivileged users on Debian 12 systems to access sensitive database credentials stored in /etc/pure-ftpd/db/mysql.conf. This file is generated with insecure permissions (0644), making it readable by any local user with command execution capabilities, including virtual users without SSH access. Attackers can exploit this vulnerability to gain administrative access to Froxlor and potentially escalate to root privileges. The vulnerability is particularly dangerous on multi-tenant hosting environments where multiple users share resources. Immediate action is recommended to mitigate risks, including applying vendor patches and restricting file permissions. The vulnerability was published on 2026-09-14, and while exploitation urgency is unclear, the potential for significant impact remains high.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-14
CVE-2024-58383 published
Froxlor vulnerability disclosed, exposing database credentials due to insecure file permissions.
Redpacketsecurity
2026-09-14
GitHub advisory released
GitHub published an advisory detailing the same vulnerability in Froxlor, confirming the risk on Debian 12 systems.
github.com

More articles in this cluster (3)

Following this threat?

Track Debian and CVE-2024-58383 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed