Description
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
Remediation
References
https://github.com/MateusTesser/CVE-2023-31718
https://github.com/frangoteam/FUXA
https://youtu.be/VCQkEGntN04
Related Vulnerabilities
CVE-2019-10746 Vulnerability in npm package mixin-deep
CVE-2017-5645 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2016-4003 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-40690 Vulnerability in maven package org.apache.santuario:xmlsec