Description
A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Import Key Handler. Performing a manipulation results in cross site scripting. The attack can be initiated remotely.
Published: 2026-01-05
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS) that can be triggered remotely through the Import Key Handler
Action: Assess
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Remyandrade
Remyandrade api Key Manager App
CPEs cpe:2.3:a:remyandrade:api_key_manager_app:1.0:*:*:*:*:*:*:*
Vendors & Products Remyandrade
Remyandrade api Key Manager App

Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester api Key Manager App
Vendors & Products Sourcecodester
Sourcecodester api Key Manager App

Tue, 06 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Import Key Handler. Performing a manipulation results in cross site scripting. The attack can be initiated remotely.
Title SourceCodester API Key Manager App Import Key cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Remyandrade Api Key Manager App
Sourcecodester Api Key Manager App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:13:12.476Z

Reserved: 2026-01-04T06:47:03.735Z

Link: CVE-2026-0580

cve-icon Vulnrichment

Updated: 2026-01-05T21:09:17.751Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-05T08:15:58.213

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-0580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T08:30:35Z

Weaknesses