Skip to content

Comments

Add CVE-2025-69981 — FUXA Unrestricted File Upload#15332

Open
trader642 wants to merge 3 commits intoprojectdiscovery:mainfrom
trader642:add-CVE-2025-69981
Open

Add CVE-2025-69981 — FUXA Unrestricted File Upload#15332
trader642 wants to merge 3 commits intoprojectdiscovery:mainfrom
trader642:add-CVE-2025-69981

Conversation

@trader642
Copy link
Contributor

CVE-2025-69981 — FUXA <= 1.2.7 Unrestricted File Upload

Description

FUXA v1.2.7 and earlier contains an unrestricted file upload vulnerability in the /api/upload endpoint. The endpoint lacks authentication, allowing unauthenticated attackers to upload arbitrary files, potentially leading to system compromise.

Detection

  • Step 1: Fingerprint — verify FUXA is running (GET /)
  • Step 2: Attempt a benign file upload to /api/upload without authentication
  • If upload succeeds (200 + JSON response), the endpoint is vulnerable

References

Severity

  • CVSS: 9.8 (Critical)
  • CWE-434: Unrestricted Upload of File with Dangerous Type

Notes

  • Part of a cluster of FUXA vulnerabilities (CVE-2025-69971, 69981, 69983)
  • Template uses non-intrusive detection: uploads a small text file with random name
  • verified: false — tested against documentation and source code analysis only

- Added 'intrusive' tag since this template uploads a file to the target
- Changed word matcher condition from OR to AND: both 'nuclei-test-' and
  'uploaded' must be present to confirm the upload succeeded on FUXA
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants