PT-2023-23429 · Fuxa · Fuxa

Mateustesser

·

Published

2023-09-21

·

Updated

2024-09-25

·

CVE-2023-31716

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FUXA versions 1.1.12 and earlier
Description The issue is related to a Local File Inclusion vulnerability. It can be exploited via the file parameter, specifically by accessing the fuxa.log file.
Recommendations For versions 1.1.12 and earlier, consider restricting access to the fuxa.log file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2023-31716
GHSA-45C3-C4C3-8RQG

Affected Products

Fuxa