Vulnerabilities
Vulnerable Software
Strapi:  >> Strapi  >> 0.0.3  Security Vulnerabilities
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.
CVSS Score
7.2
EPSS Score
0.816
Published
2019-12-05
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
CVSS Score
9.8
EPSS Score
0.94
Published
2019-11-07


Contact Us

Shodan ® - All rights reserved