A vulnerability was found in ProFTPd up to 1.3.9a. It has been declared as critical. This affects the function
sqltab_fetch_clients_cb of the file contrib/mod_wrap2_sql.c. The manipulation results in sql injection.
This vulnerability was named CVE-2026-44331. The attack may be performed from remote. There is no available exploit.
Applying a patch is advised to resolve this issue.