{"advisories":[{"id":"GHSA-r87q-fq37-pvr6","source":"ghsa","title":"A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA","url":"https://github.com/advisories/GHSA-r87q-fq37-pvr6"}],"cve":"CVE-2023-33831","epss":{"score":0.25951},"mitre":{"cpes":[],"created":"2023-09-18T00:00:00+00:00","description":"A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2023/33xxx/CVE-2023-33831.json","references":["https://github.com/rodolfomarianocy/Unauthenticated-RCE-FUXA-CVE-2023-33831","https://youtu.be/Xxa6yRB2Fpw"],"title":null,"updated":"2024-09-25T18:46:00.773000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:frangoteam:fuxa:1.1.13:*:*:*:*:*:*:*"],"created":"2023-09-18T20:15:09.377000+00:00","description":"A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2023/CVE-2023-33831.json","references":["https://github.com/rodolfomarianocy/Unauthenticated-RCE-FUXA-CVE-2023-33831","https://youtu.be/Xxa6yRB2Fpw"],"title":null,"updated":"2026-06-17T06:02:20.207000+00:00","vendors":["frangoteam","frangoteam$PRODUCT$fuxa"],"weaknesses":["CWE-77"]},"opencve":{"changes":[{"created":"2024-09-25T19:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"5132b19d-4070-4d52-8673-abc7f11015fa"}],"cpes":{"data":["cpe:2.3:a:frangoteam:fuxa:1.1.13:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2023-09-18T00:00:00+00:00","provider":"mitre"},"description":{"data":"A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.25951},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/rodolfomarianocy/Unauthenticated-RCE-FUXA-CVE-2023-33831","https://youtu.be/Xxa6yRB2Fpw"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2024-11-21T08:06:02.613000+00:00","provider":"nvd"},"vendors":{"data":["frangoteam","frangoteam$PRODUCT$fuxa"],"providers":["nvd"]},"weaknesses":{"data":["CWE-77"],"providers":["nvd"]}},"vulnrichment":{"cpes":[],"created":"2023-09-18T00:00:00+00:00","description":"A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2024-09-25T18:45:57.289000+00:00","vendors":[],"vulnrichment_repo_path":"2023/33xxx/CVE-2023-33831.json","weaknesses":[]}}