CVE-2023-36472
CVSS 3.1 Score 5.7 of 10 (medium)
Details
Published Sep 15, 2023
Updated: Sep 21, 2023
CWE ID 200
Summary
CVE-2023-36472 is a vulnerability affecting the open-source headless content management system, Strapi, prior to version 4.11.7. An unauthorized user with configure view permissions can exploit this issue and gain unauthorized access to user reset password tokens. This vulnerability arises due to the `/content-manager/relations` route not removing private fields or restricting their selection. This security flaw has been rectified in Strapi version 4.11.7.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- strapi
Affected Vendors
- Strapi