vendor:
Strapi
by:
David Anglada [CodiObert]
9,8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Strapi
Affected Version From: 3.0.0-beta
Affected Version To: 3.0.0-alpha
Patch Exists: YES
Related CWE: CVE-2019-18818
CPE: a:strapi:strapi:3.0.0-beta
Metasploit:
N/A
Other Scripts:
N/A
Tags: cve2019,strapi,auth-bypass,intrusive,edb,cve
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'vendor': 'strapi', 'product': 'strapi'}
Platforms Tested: Linux
2021
Strapi 3.0.0-beta – Set Password (Unauthenticated)
strapi CMS before 3.0.0-beta.17.5 allows admin password resets because it mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
Mitigation:
Upgrade to Strapi 3.0.1 or later.