CVE-2023-36472

CVSS V2 None CVSS V3 None
Description
Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/relations` route does not remove private fields or ensure that they can't be selected. This issue is fixed in version 4.11.7.
Overview
  • CVE ID
  • CVE-2023-36472
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-15T18:54:34.072Z
  • Last Modified Date
  • 2023-09-19T16:39:09.135Z
History
Created Old Value New Value Data Type Notes
2024-06-25 16:22:49 Added to TrackCVE