ProFTPd upstream has released version 1.3.8b to fix CVE-2023-48795. From the changelog:
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2023-0356.json"