CVE-2025-3801
songquanpeng one-api System Setting cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content/About System/Footer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Es wurde eine Schwachstelle in songquanpeng one-api bis 0.6.10 ausgemacht. Sie wurde als problematisch eingestuft. Es betrifft eine unbekannte Funktion der Komponente System Setting Handler. Durch das Beeinflussen des Arguments Homepage Content/About System/Footer mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-04-18 CVE Reserved
- 2025-04-19 CVE Published
- 2025-04-20 EPSS Updated
- 2025-04-21 CVE Updated
- 2025-04-21 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.305655 | Vdb Entry | |
https://vuldb.com/?submit.554702 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/yaowenxiao721/Poc/blob/main/One-API/One-API-poc.md | 2025-04-21 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.0 Search vendor "Songquanpeng" for product "One-api" and version "0.6.0" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.1 Search vendor "Songquanpeng" for product "One-api" and version "0.6.1" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.2 Search vendor "Songquanpeng" for product "One-api" and version "0.6.2" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.3 Search vendor "Songquanpeng" for product "One-api" and version "0.6.3" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.4 Search vendor "Songquanpeng" for product "One-api" and version "0.6.4" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.5 Search vendor "Songquanpeng" for product "One-api" and version "0.6.5" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.6 Search vendor "Songquanpeng" for product "One-api" and version "0.6.6" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.7 Search vendor "Songquanpeng" for product "One-api" and version "0.6.7" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.8 Search vendor "Songquanpeng" for product "One-api" and version "0.6.8" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.9 Search vendor "Songquanpeng" for product "One-api" and version "0.6.9" | en |
Affected
| ||||||
Songquanpeng Search vendor "Songquanpeng" | One-api Search vendor "Songquanpeng" for product "One-api" | 0.6.10 Search vendor "Songquanpeng" for product "One-api" and version "0.6.10" | en |
Affected
|