Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7g56-fwxj-cm23

Опубликовано: 03 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.1

Описание

FUXA contains an Unrestricted File Upload vulnerability

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the /api/upload API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.

Пакеты

Наименование

fuxa-server

npm
Затронутые версииВерсия исправления

<= 1.2.7

Отсутствует

EPSS

Процентиль: 21%
0.00069
Низкий

8.1 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
4 дня назад

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.

EPSS

Процентиль: 21%
0.00069
Низкий

8.1 High

CVSS4

Дефекты

CWE-306