PT-2020-13804 · Strapi · Strapi

Published

2020-06-19

·

Updated

2022-05-24

·

CVE-2020-13961

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Strapi versions prior to 3.0.2
Description The issue allows a remote authenticated attacker to bypass security restrictions. This is because templates are stored in a global variable without any sanitation, enabling an attacker to update the email template for both password reset and account confirmation emails by sending a specially crafted request.
Recommendations For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to template updates to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13961
GHSA-65WV-528R-M892

Affected Products

Strapi