CyberRota Analysis
AI-GeneratedFlextype CMS versions up to 1.0.0-alpha.3 are vulnerable due to the acceptance of API authentication credentials via URL query string parameters in REST API routes. This flaw allows attackers with access to web server logs or monitoring tools to extract valid API token pairs, potentially granting them full access to the API. Organizations using this CMS should prioritize remediation to mitigate the risk of unauthorized API access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.