FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Link | Tags |
---|---|
https://github.com/frangoteam/FUXA | product |
https://youtu.be/VCQkEGntN04 | third party advisory exploit |
https://github.com/MateusTesser/CVE-2023-31718 | third party advisory |