Record summary

CVE-2023-39345 has a selected CVSS score of 7.6 (high).

Description

strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in version 4.13.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 4, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

CVE List4.0.0 to < 4.13.1affected
>= 4.0.0, < 4.13.1affected

@strapi/plugin-users-permissions

Browse npm / @strapi/plugin-users-permissions
GitHub Advisory4.0.0 to < 4.13.1 · Fixed in 4.13.1affected
GitHub Advisory4.0.0 to < 4.13.1 · Fixed in 4.13.1affected

References

4