Логотип exploitDog
bind:CVE-2024-56143
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-56143

Количество 2

Количество 2

nvd логотип

CVE-2024-56143

4 месяца назад

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin passwords and reset tokens, by crafting queries with the lookup parameter. This vulnerability is fixed in 5.5.2.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-495j-h493-42q2

4 месяца назад

Strapi Allows Unauthorized Access to Private Fields via parms.lookup

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-56143

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin passwords and reset tokens, by crafting queries with the lookup parameter. This vulnerability is fixed in 5.5.2.

CVSS3: 8.2
0%
Низкий
4 месяца назад
github логотип
GHSA-495j-h493-42q2

Strapi Allows Unauthorized Access to Private Fields via parms.lookup

CVSS3: 8.2
0%
Низкий
4 месяца назад

Уязвимостей на страницу