Description
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
Remediation
References
https://github.com/MateusTesser/CVE-2023-31718
https://youtu.be/VCQkEGntN04
https://github.com/frangoteam/FUXA
Related Vulnerabilities
CVE-2022-0624 Vulnerability in npm package parse-path
CVE-2018-20676 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2020-1963 Vulnerability in maven package org.apache.ignite:ignite-core
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component
CVE-2023-25761 Vulnerability in maven package org.jenkins-ci.plugins:junit