strapi CMS before 3.0.0-beta.17.5 allows admin password resets because it mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
id: CVE-2019-18818
info:
name: strapi CMS <3.0.0-beta.17.5 - Admin Password Reset
author: ideal
...