frangoteam FUXA
cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*
- 1.2.7
A remote code execution vulnerability exists in FUXA version 1.2.7, specifically within the project import feature. The application fails to adequately sanitize or sandbox user-provided scripts in imported project files, allowing an attacker to upload a malicious project that executes system commands, potentially leading to a complete system compromise.
Exploitation of this vulnerability allows for remote code execution on the server where FUXA is running.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.