VDB
Sign up
MEDIUM4.6

GHSA-4vm8-j95f-j6v5

Strapi 4.1.12 Cross-site Scripting via crafted file

Details

An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted file. After an authenticated attacker uploads a file containing a malicious URL, a victim copies and pastes the malicious URL into a new tab to receive the XSS payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@strapi/strapi
Introduced in: 0

No fixed version published yet for @strapi/strapi (npm). Pin to a known-safe version or switch to an alternative.

References