THREAT OPS › Threat News › [NVD] CVE-2024-58383 (HIGH 7.3) — Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are
[NVD] CVE-2024-58383 (HIGH 7.3) — Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are
CVE-2024-58383 CVSS: 7.3 HIGH Published: 2026-09-14T13:17:15.150
Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian 12), any unprivi
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2024-58383cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-58383