Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-69971 PoC — FUXA 安全漏洞

Source
Associated Vulnerability
Title:FUXA 安全漏洞 (CVE-2025-69971)
Description:FUXA是frangoteam开源的一个基于web的过程可视化软件。 FUXA 1.2.7版本存在安全漏洞,该漏洞源于server/api/jwt-helper.js中使用硬编码密钥签署和验证JWT令牌,可能导致远程攻击者伪造有效的管理员令牌并绕过身份验证以获得完全管理权限。
Description
FUXA v1.2.7 contains a hardcoded credentials vulnerability caused by use of a hard-coded secret key in server/api/jwt-helper.js, letting remote attackers forge admin tokens and bypass authentication, exploit requires no special conditions.
File Snapshot

id: CVE-2025-69971 info: name: FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication Bypass autho ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.