Strapi是一套开源的内容管理系统(CMS)。 Strapi 4.12.1及之前版本存在安全漏洞,该漏洞源于login功能存在速率限制,导致攻击者可以通过暴力攻击进行未授权登录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2023-37263 | 6.8 MEDIUM | Strapi's field level permissions not being respected in relationship title |
| CVE-2023-36472 | 5.8 MEDIUM | Strapi may leak sensitive user information, user reset password, tokens via content-manage |
No comments yet