Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwp3-ppxm-vg9c

Опубликовано: 10 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

EPSS

Процентиль: 25%
0.00317
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-598

Связанные уязвимости

CVSS3: 5.9
nvd
13 дней назад

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

EPSS

Процентиль: 25%
0.00317
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-598