Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-58383— Froxlor before 2.2.0 Insecure File Permissions mysql.conf

Quick assessment

Affected
froxlor froxlor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Froxlor 2.2.0 之前(受影响版本包括 2.2.0-rc3 及更早版本)会通过位于 目录下的 XML 配置模板生成权限为 0644 的 文件,尽管该文件中包含了 Froxlor SQL 用户的密码。在父目录对所有用户可读的系统中(例如 Debian 12 的默认配置),任何能够在主机上执行命令或代码的非特权本地用户——包括那些没有 SSH 访问权限、但可以上传 PHP/CGI 脚本的虚拟用户——都可以读取该文件并获取 Froxlor 数据库的凭据。攻击者随后可以利用数据库访问权限修改管理员的密码哈希和 T

CVSS 7.3 · High

Possible ATT&CK Techniques 1 AI

T1079
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-58383

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Froxlor before 2.2.0 Insecure File Permissions mysql.conf
Source: CVE Program / CVE List V5
Vulnerability Description
Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian 12), any unprivileged local user able to execute commands or code on the host — including virtual users without SSH access who can upload PHP/CGI scripts — can read the file and obtain the Froxlor database credentials. Database access can then be leveraged to alter an administrator's password hash and TOTP seed, log in as a Froxlor administrator, and ultimately gain root privileges. Only instances configured to use pure-ftpd are affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
froxlor froxlor 0 ~ 2.2.0 -

II. Public POCs for CVE-2024-58383

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-58383

登录查看更多情报信息。

Vendor Advisories for CVE-2024-58383 (2)

Same Patch Batch · froxlor · 2026-09-14 · 4 CVEs total

CVE-2026-90937 9.9 CRITICAL froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL
CVE-2026-90935 4.3 MEDIUM Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API
CVE-2026-90936 4.3 MEDIUM Froxlor before 2.3.7 Information Disclosure via customer_email.php

IV. Related Vulnerabilities

V. Comments for CVE-2024-58383

No comments yet


Leave a comment