Impact
The Steedos Platform through version 3.0.15‑beta.47 contains a reflected cross-site scripting flaw in the anonymous /api/page/render endpoint. The vulnerability arises because query parameters are not An attacker can craft a malicious URL withApi or data parameters, causing arbitrary JavaScript to execute in the victim’s browser session. This script can then steal X‑Auth‑Token credentials that the user has stored in the session, enabling credential theft.
Affected Systems
All deployments of the Steedos Platform that expose the default anonymous /api/page/render API endpoint and run a version of15‑beta.47 are affected. The vulnerability is present in any environment that uses the standard configuration of the platform and allows anonymous access to that endpoint.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS score of <1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation but still possible. However, the endpoint is publicly reachable and the payload can be delivered via a simple hyperlink, meaning that an attacker could realistically inject malicious scripts into a victim’s session. Successful exploitation would lead to credential theft that could allow lateral movement or unauthorized access within, especially for environments that rely on the default anonymous access policy.
OpenCVE Enrichment