Impact
Flextype CMS versions up to 1.0.0-alpha.3 allows authentication credentials to be provided in URL query string parameters on its REST API routes. This flaw lets an unauthorized party recover valid API token pairs that grant full API access when they can read web server, proxy, or monitoring logs, thus potentially compromising the entire system via the API. The vulnerability is a data exposure weakness (CWE-598) that directly compromises confidentiality and integrity of API operations.
Affected Systems
Victims are installations of Flextype CMS from the flextype:flextype vendor, specifically the 1.0.0-alpha.3 release and any earlier builds that use the same API handling code. No other versions or products were identified as affected by this specific query string flaw.
Risk and Exploitability
The flaw has a CVSS score of 8.2, indicating high severity. Because the EPSS score is not available, the current exploitation probability is uncertain but the vulnerability is listed as not included in CISA KEV. Attackers would typically obtain the tokens by inspecting log files or traffic records on the web server or network; the flaw does not require remote code execution or privilege escalation beyond reading logs, so it can be exploited by any entity that can access these logs.
OpenCVE Enrichment