Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2025-69985

7 месяцев назад

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r4r-4jp4-wwf9

7 месяцев назад

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-69985

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.

CVSS3: 9.8
6%
Низкий
7 месяцев назад
github логотип
GHSA-4r4r-4jp4-wwf9

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

CVSS3: 9.8
6%
Низкий
7 месяцев назад

Уязвимостей на страницу