PT-2021-17761 · Strapi · Strapi
Jürgen Zöller
·
Published
2021-05-06
·
Updated
2021-10-06
·
CVE-2021-28128
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Strapi versions prior to 3.6.1 is not mentioned, however, the version 3.6.0 is mentioned as vulnerable, so we can say
Strapi versions 3.6.0 and earlier
Description:
The admin panel in Strapi allows users to change their own password without entering the current password. An attacker who gains access to a valid session can exploit this to take over an account by changing the password.
Recommendations:
For Strapi versions 3.6.0 and earlier, update to version 3.6.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the admin panel to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Strapi