CVE-2023-31718: High severity frangoteam FUXA vulnerability
Published Sep 21, 2023
·Updated
FUXA <= 1.1.12 is vulnerable to Local File Inclusion via /api/download.
Other sources
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
Affected Software
2 affected components
frangoteam FUXA<=1.1.12
npm/fuxa-server<=1.1.12
Event History
Sep 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 22, 2023
Advisory Published
12:30 AM
Frequently Asked Questions
1
What is the vulnerability ID for FUXA?
The vulnerability ID for FUXA is CVE-2023-31718.
2
What is the severity of CVE-2023-31718?
The severity of CVE-2023-31718 is high with a severity value of 7.5.
3
How does CVE-2023-31718 affect FUXA?
CVE-2023-31718 affects FUXA <= 1.1.12 by enabling local file inclusion via `/api/download`.
4
What is the affected software version for CVE-2023-31718?
The affected software version for CVE-2023-31718 is FUXA <= 1.1.12.
5
How can I fix the vulnerability CVE-2023-31718?
To fix the vulnerability CVE-2023-31718, you should upgrade FUXA to a version higher than 1.1.12.