HIGH 7.2 npm
Command Injection in strapi
GHSA-9p2w-rmx4-9mw7 · CVE-2019-19609
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Versions of strapi before 3.0.0-beta.17.8 are vulnerable to Command Injection. The package fails to sanitize plugin names in the /admin/plugins/install/ route. This may allow an authenticated attacker with admin privileges to run arbitrary commands in the server.
Recommendation
Upgrade to version 3.0.0-beta.17.8 or later
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2019-19609
- WEB https://github.com/strapi/strapi/pull/4636
- WEB https://bittherapy.net/post/strapi-framework-remote-code-execution
- PACKAGE https://github.com/strapi/strapi
- WEB https://www.npmjs.com/advisories/1424
- WEB http://packetstormsecurity.com/files/163940/Strapi-3.0.0-beta.17.7-Remote-Code-Execution.html
- WEB http://packetstormsecurity.com/files/163950/Strapi-CMS-3.0.0-beta.17.4-Remote-Code-Execution.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes