Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FUXA 安全漏洞
Vulnerability Description
FUXA是frangoteam开源的一个基于web的过程可视化软件。 FUXA 1.2.7版本存在安全漏洞,该漏洞源于/api/upload API端点缺乏身份验证机制,可能导致未经身份验证的远程攻击者上传任意文件,从而覆盖关键系统文件或上传恶意脚本以执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A