CRITICAL 9.8 npm

Strapi allows unauthenticated attacker to reset admin password without valid reset token

GHSA-6xc2-mj39-q599 · CVE-2019-18818

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Versions of strapi prior to 3.0.0-beta.17.5 are vulnerable to Privilege Escalation. The password reset routes allows an unauthenticated attacker to reset an admin's password without providing a valid password reset token.

Recommendation

Upgrade to version 3.0.0-beta.17.5 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes