one-api Cross-site Scripting vulnerability
Moderate severity
GitHub Reviewed
Published
Apr 19, 2025
to the GitHub Advisory Database
•
Updated Apr 21, 2025
Description
Published by the National Vulnerability Database
Apr 19, 2025
Published to the GitHub Advisory Database
Apr 19, 2025
Reviewed
Apr 21, 2025
Last updated
Apr 21, 2025
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References