CVE-2023-31719

CRITICAL

FUXA <= 1.1.12 - SQL Injection

Title source: llm

Description

FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

Exploits (2)

github WORKING POC 6 stars
by AikidoSec · javascriptpoc
https://github.com/AikidoSec/zen-0-days/tree/main/node/CVE-2023-31719
nomisec WORKING POC
by MateusTesser · poc
https://github.com/MateusTesser/CVE-2023-31719

Scores

CVSS v3 9.8
EPSS 0.6546
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
frangoteam/fuxa < 1.1.12
npm/fuxa-server 0npm
Published Sep 22, 2023
Tracked Since Feb 18, 2026