Description
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
Remediation
References
https://github.com/frangoteam/FUXA
https://github.com/MateusTesser/CVE-2023-31717
https://youtu.be/IBMXTEI_5wY
Related Vulnerabilities
CVE-2018-8039 Vulnerability in maven package org.apache.cxf:cxf-rt-transports-http
CVE-2021-32818 Vulnerability in npm package haml-coffee
CVE-2021-3664 Vulnerability in npm package url-parse
CVE-2019-1003053 Vulnerability in maven package org.jenkins-ci.plugins:hockeyapp
CVE-2020-6460 Vulnerability in maven package org.webjars.npm:electron