Description
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
Remediation
References
https://github.com/frangoteam/FUXA
https://github.com/MateusTesser/CVE-2023-31718
https://youtu.be/VCQkEGntN04
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package bitcionjs
CVE-2021-46708 Vulnerability in maven package com.microfocus.webjars:swagger-ui-dist
CVE-2022-23437 Vulnerability in maven package xerces:xercesimpl
CVE-2018-21270 Vulnerability in npm package stringstream
CVE-2019-9512 Vulnerability in maven package io.netty:netty-codec-http2