Junglewise Threat Intelligence

CVE-2023-31719: FUXA SQL injection in sign-in endpoint

CVE-2023-31719 · Severity: low · CVSS 3.1 · Published 2023-09-22

Technologies: Fuxa-Server. Vendors: npm.

Executive brief

FUXA is an open-source industrial control and automation platform. A SQL injection vulnerability in the sign-in endpoint allows an unauthenticated attacker to execute arbitrary SQL commands by manipulating the username parameter, potentially leading to unauthorized data access or authentication bypass without requiring any user interaction.

Technical details

The vulnerability is a classic SQL injection (CWE-89) in the /api/signin endpoint where the username parameter is not properly sanitized before being used in a database query. An attacker can inject arbitrary SQL code via a POST request to the JSON username field (e.g., using OR conditions and time-delay payloads). The attack requires no authentication or user interaction and is reachable over the network. Successful exploitation allows an attacker to read, modify, or delete database records, potentially bypassing login controls and accessing sensitive system data. FUXA versions up to and including 1.1.12 are affected.

Affected products

  • FUXA fuxa-server <= 1.1.12

Timeline

  • 2023-09-22: disclosed
  • 2023-09-22: advisory

References

Related threats