Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 15:17
Updated : 2026-09-15 15:17
NVD link : CVE-2026-88897
Mitre link : CVE-2026-88897
CVE.ORG link : CVE-2026-88897
JSON object : View
Products Affected
No product.
CWE
CWE-598
Use of HTTP Request With Sensitive Query String
