FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-03T17:40:23.602Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69981
No data.
Status : Received
Published: 2026-02-03T18:16:17.467
Modified: 2026-02-03T18:16:17.467
Link: CVE-2025-69981
No data.
OpenCVE Enrichment
No data.