CVE-2025-69983: OS Command Injection
FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported project files. An attacker can upload a malicious project containing system commands, leading to full system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69983?
CVE-2025-69983 has a high severity due to its potential for Remote Code Execution.
How do I fix CVE-2025-69983?
To fix CVE-2025-69983, upgrade to a version of FUXA later than 1.2.7 that addresses the vulnerability.
What can an attacker do with CVE-2025-69983?
An attacker can exploit CVE-2025-69983 to upload a malicious project, execute system commands, and potentially compromise the entire system.
What versions of FUXA are affected by CVE-2025-69983?
CVE-2025-69983 affects FUXA version 1.2.7.
Is there a known exploit for CVE-2025-69983?
Yes, CVE-2025-69983 is vulnerable to exploitation via improperly sanitized user-supplied scripts in project imports.