VDB
Sign up
MEDIUM6.5

GHSA-65wv-528r-m892

Improper Input Validation in strapi

Quick fix

GHSA-65wv-528r-m892 — strapi: upgrade to the fixed version with the command below.

npm install strapi@3.0.2

Details

Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation. By sending a specially crafted request, an attacker could exploit this vulnerability to update the email template for both password reset and account confirmation emails.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/strapi
Introduced in: 0Fixed in: 3.0.2
Fixnpm install strapi@3.0.2

References