1.3.1
5 years ago
15 days ago
Known vulnerabilities in the @frangoteam/fuxa package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to Directory Traversal due to the improper sanitization of nested traversal sequences (e.g., How to fix Directory Traversal? A fix was pushed into the | * |
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to Missing Authorization in the scheduler endpoint. An attacker can gain unauthorized access to create, modify, or delete schedules by sending crafted requests to the server. This can result in forcing connected devices to specific states, values, or executing existing scripts remotely. How to fix Missing Authorization? A fix was pushed into the | >=1.2.8 |
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the How to fix Missing Authentication for Critical Function? A fix was pushed into the | >=1.2.8 |
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to SQL Injection via the How to fix SQL Injection? There is no fixed version for | * |
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? There is no fixed version for | * |
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to SQL Injection via the How to fix SQL Injection? There is no fixed version for | * |
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the How to fix Remote Code Execution (RCE)? There is no fixed version for | >=0.0.0 |
@frangoteam/fuxa is a Web-based Process Visualization (SCADA/HMI/Dashboard) software Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to obtain sensitive information from the server's internal environment and services. How to fix Server-side Request Forgery (SSRF)? There is no fixed version for | * |