FUXA v1.2.7 contains a hardcoded credentials vulnerability caused by use of a hard-coded secret key in server/api/jwt-helper.js, letting remote attackers forge admin tokens and bypass authentication, exploit requires no special conditions.
id: CVE-2025-69971
info:
name: FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication Bypass
autho
...