PT-2023-25582 · Strapi · Strapi

Boegie19

·

Published

2023-09-13

·

Updated

2023-09-21

·

CVE-2023-36472

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Strapi versions prior to 4.11.7
Description The issue allows an unauthorized actor to access user reset password tokens if they have configure view permissions. The /content-manager/relations route does not remove private fields or ensure that they can't be selected. This can lead to privilege escalation, as a non-admin user can obtain the reset token of an admin user's account and use it to reset the password.
Recommendations For versions prior to 4.11.7, update to version 4.11.7 to resolve the issue. As a temporary workaround, consider restricting access to the /content-manager/relations route or disabling the configure view permission for non-admin users until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-36472
GHSA-V8GG-4MQ2-88Q4

Affected Products

Strapi