GHSA-65wv-528r-m892

Source
https://github.com/advisories/GHSA-65wv-528r-m892
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-65wv-528r-m892/GHSA-65wv-528r-m892.json
Aliases
Published
2022-05-24T17:21:16Z
Modified
2023-11-08T04:02:24.509618Z
Details

Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation. By sending a specially crafted request, an attacker could exploit this vulnerability to update the email template for both password reset and account confirmation emails.

References

Affected packages

npm / strapi

Package

Name
strapi

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
3.0.2