Beveiligingsadvies

CVE-2026-88897

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-10 14:46:36
Laatst bijgewerkt 2026-09-10 14:46:36
Toegewezen door VulnCheck
CVSS-score 8.2
Status PUBLISHED

Beschrijving

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.