Description
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
Remediation
References
https://github.com/frangoteam/FUXA
https://github.com/MateusTesser/CVE-2023-31719
https://youtu.be/cjb2KYpV6dY
Related Vulnerabilities
CVE-2022-36527 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2022-35915 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2020-7743 Vulnerability in maven package org.webjars:mathjs
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-29256 Vulnerability in maven package org.webjars.npm:sharp