Skip to main content
HIGH

CVE-2024-58383

CVSS v3

7.3

HIGH

EPSS Score

0.1 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian 12), any unprivileged local user able to execute commands or code on the host — including virtual users without SSH access who can upload PHP/CGI scripts — can read the file and obta

Technical details

Published
2026-09-14
Last Modified
2026-09-14

Frequently asked questions

What is CVE-2024-58383?

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian 12), any unprivileged local user able to execute commands or code on the host — including virtual users without SSH access who can upload PHP/CGI scripts — can read the file and obta

Is CVE-2024-58383 actively exploited?

Active exploitation of CVE-2024-58383 has not been confirmed. Its EPSS score was 0.1% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2024-58383?

CVE-2024-58383 has a CVSS v3 base score of 7.3 (HIGH severity).

Is CVE-2024-58383 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key