Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Convly

#37095of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2020-16757
7.5
2020-10-22
Strapi · Strapi · CVE-2020-27665
**Name of the Vulnerable Software and Affected Versions** Strapi versions prior to 3.2.5 **Description** The issue arises from the lack of `admin::hasPermissions` restriction for CTB (content-type-builder) routes. This means that there are no proper access controls in place for these specific routes, potentially allowing unauthorized access or actions. **Recommendations** For versions prior to 3.2.5, update to version 3.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to CTB routes to minimize the risk of exploitation.