Critical Vulnerability in Froxlor Exposes Database Credentials
Article Content
- •CVE-2024-58383 affects Froxlor versions before 2.2.0.
- •Database credentials are exposed due to insecure file permissions.
- •Immediate patching and permission restrictions are critical for mitigation.
A critical vulnerability, CVE-2024-58383, affects Froxlor versions before 2.2.0, allowing unprivileged users on Debian 12 systems to access sensitive database credentials stored in /etc/pure-ftpd/db/mysql.conf. This file is generated with insecure permissions (0644), making it readable by any local user with command execution capabilities, including virtual users without SSH access. Attackers can exploit this vulnerability to gain administrative access to Froxlor and potentially escalate to root privileges. The vulnerability is particularly dangerous on multi-tenant hosting environments where multiple users share resources. Immediate action is recommended to mitigate risks, including applying vendor patches and restricting file permissions. The vulnerability was published on 2026-09-14, and while exploitation urgency is unclear, the potential for significant impact remains high.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Debian and CVE-2024-58383 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…