Description
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
Remediation
References
https://github.com/frangoteam/FUXA
https://github.com/MateusTesser/CVE-2023-31717
https://youtu.be/IBMXTEI_5wY
Related Vulnerabilities
CVE-2023-30527 Vulnerability in maven package org.jenkins-ci.plugins:wso2id-oauth
CVE-2018-20677 Vulnerability in maven package org.fujion.webjars:bootstrap
CVE-2017-16093 Vulnerability in npm package cyber-js
CVE-2020-4035 Vulnerability in npm package @nozbe/watermelondb
CVE-2021-43138 Vulnerability in maven package org.webjars.bowergithub.caolan:async