Songquanpeng One-API Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Songquanpeng One-API versions through 0.6.10. This issue resides within the System Setting Handler component, specifically in the Homepage Content, About System, and Footer fields. The vulnerability allows for the injection of malicious scripts that are executed in the context of other users' sessions. The issue can be exploited remotely, and has been publicly disclosed.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.

Reproduction

To reproduce this vulnerability, log in as a user with privileges to edit system settings. Navigate to the Homepage Content, Footer, or About System fields and insert a script tag containing a JavaScript alert. Once the content is saved, the script will execute when the page is viewed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.