Strapi是一套开源的内容管理系统(CMS)。 Strapi 4.19.1之前版本存在安全漏洞,该漏洞源于当超级管理员创建一个集合,其中集合中的项目与另一个集合有关联时,具有作者角色的另一个用户可以看到他们未创建的关联项目列表。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-34065 | 7.1 HIGH | @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication |
| CVE-2024-31217 | 5.3 MEDIUM | @strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling |
No comments yet