Описание
Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The /content-manager/relations route does not remove private fields or ensure that they can't be selected. This issue is fixed in version 4.11.7.
Ссылки
- Release Notes
- ExploitThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.11.7 (исключая)
cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00137
Низкий
5.8 Medium
CVSS3
5.7 Medium
CVSS3
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 5.8
github
больше 2 лет назад
Strapi may leak sensitive user information, user reset password, tokens via content-manager views
EPSS
Процентиль: 34%
0.00137
Низкий
5.8 Medium
CVSS3
5.7 Medium
CVSS3
Дефекты
CWE-200