Impact
Flextype CMS versions up to 1.0.0‑alpha.3 contain a path traversal flaw in the Entries REST API. The API accepts id and new_id parameters without proper validation, allowing authenticated API token holders to craft requests that escape the intended entries directory. Attackers can read the contents of any file on the filesystem, create new files, or overwrite existing ones beyond the entries directory, potentially modifying configuration files or deploying malicious code. This vulnerability is categorized as CWE‑22 and can lead to significant confidentiality, integrity, and availability impacts if exploited.
Affected Systems
All installations of Flextype CMS up to and including version 1.0.0‑alpha.3 are affected. The vulnerability exists in the core Entries.php component of the software, impacting sites that expose the Entries REST API and issue API tokens to users. Any user or application with possession of a valid API token is vulnerable to the attack. No higher or lower versions were explicitly stated as unaffected, so the safety recommendation applies to the entire pre‑1.0.0‑alpha.3 release line.
Risk and Exploitability
The CVSS score of 7.2 denotes high severity and the EPSS score of < 1% indicates a very low historical exploitation probability. Because the flaw requires an authenticated API token, legitimate users who hold such tokens could be abused. The exposed network‑accessible Entries REST API allows remote attackers to craft authenticated requests that utilize traversal sequences in the id or new_id parameters. Though the EPSS suggests exploitation is unlikely, the high impact, remote nature, and absence from the CISA KEV catalog mean the vulnerability could be used to manipulate arbitrary files, potentially leading to code execution or defacement.
OpenCVE Enrichment