Vulnerabilities/

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA

Severity:
High

Description

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@frangoteam/fuxa
Anything's wrong? Let us know Last updated on November 11, 2023

This issue is available in SmartScanner Professional

See Pricing