ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Source: NVD ↗ · CISA KEV Catalog ↗