In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.