Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40277
HistoryApr 25, 2023 - 4:48 a.m.

Sensitive Information Disclosure

2023-04-2504:48:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
information disclosure
vulnerability
@strapi/strapi
unauthorized access
api

0.001 Low

EPSS

Percentile

51.3%

@strapi/strapi is vulnerable to Information Disclosure. An unauthenticated attacker can filter users by columns that contain sensitive information and infer the values by the changes in the API responses, which leads to hijacking Strapi administrator accounts and gaining unauthorized Strapi Super Administrator access by leaking the password reset token and changing the admin password.

0.001 Low

EPSS

Percentile

51.3%