Executive brief
FUXA is an open-source industrial control and automation platform. A SQL injection vulnerability in the sign-in endpoint allows an unauthenticated attacker to execute arbitrary SQL commands by manipulating the username parameter, potentially leading to unauthorized data access or authentication bypass without requiring any user interaction.
Technical details
The vulnerability is a classic SQL injection (CWE-89) in the /api/signin endpoint where the username parameter is not properly sanitized before being used in a database query. An attacker can inject arbitrary SQL code via a POST request to the JSON username field (e.g., using OR conditions and time-delay payloads). The attack requires no authentication or user interaction and is reachable over the network. Successful exploitation allows an attacker to read, modify, or delete database records, potentially bypassing login controls and accessing sensitive system data. FUXA versions up to and including 1.1.12 are affected.
Affected products
- FUXA fuxa-server <= 1.1.12
Timeline
- 2023-09-22: disclosed
- 2023-09-22: advisory