PT-2022-19900 · Strapi · Strapi

Yuta Morioka

·

Published

2022-06-13

·

Updated

2022-06-22

·

CVE-2022-29894

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Strapi versions 3.x.x and earlier
Description The issue is related to a stored cross-site scripting vulnerability in the file upload function. This vulnerability allows an arbitrary script to be executed on the web browser of the user who is logging in to the product with administrative privilege.
Recommendations For Strapi versions 3.x.x and earlier, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29894
GHSA-MCQM-6FF4-53QX

Affected Products

Strapi