Description
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
Remediation
References
https://github.com/frangoteam/FUXA
https://github.com/MateusTesser/CVE-2023-31718
https://youtu.be/VCQkEGntN04
Related Vulnerabilities
CVE-2020-28052 Vulnerability in maven package bouncycastle:bcprov-jdk14
CVE-2018-11796 Vulnerability in maven package org.apache.tika:tika-core
CVE-2016-10616 Vulnerability in npm package openframe-image
CVE-2020-2304 Vulnerability in maven package org.jenkins-ci.plugins:subversion
CVE-2020-2115 Vulnerability in maven package org.jenkins-ci.plugins:nunit