Vulnerabilities
Vulnerable Software
Strapi:  >> Strapi  >> 3.0.0  Security Vulnerabilities
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
CVSS Score
5.4
EPSS Score
0.003
Published
2020-10-22
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation. By sending a specially crafted request, an attacker could exploit this vulnerability to update the email template for both password reset and account confirmation emails.
CVSS Score
6.5
EPSS Score
0.006
Published
2020-06-19
A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.
CVSS Score
4.9
EPSS Score
0.006
Published
2020-02-04
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.
CVSS Score
7.2
EPSS Score
0.716
Published
2019-12-05
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
CVSS Score
9.8
EPSS Score
0.94
Published
2019-11-07


Contact Us

Shodan ® - All rights reserved