MEDIUM 4.6 npm
Strapi 4.1.12 Cross-site Scripting via crafted file
GHSA-4vm8-j95f-j6v5 · CVE-2022-32114
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted file. After an authenticated attacker uploads a file containing a malicious URL, a victim copies and pastes the malicious URL into a new tab to receive the XSS payload.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-32114
- WEB https://docs.strapi.io/dev-docs/configurations/public-assets
- WEB https://docs.strapi.io/user-docs/users-roles-permissions/configuring-administrator-roles
- WEB https://github.com/bypazs/strapi
- PACKAGE https://github.com/strapi/strapi
- WEB https://github.com/strapi/strapi/blob/d9277d616b4478a3839e79e47330a4aaf167a2f1/packages/core/content-type-builder/admin/src/components/AllowedTypesSelect/index.js#L14
- WEB https://github.com/strapi/strapi/blob/d9277d616b4478a3839e79e47330a4aaf167a2f1/packages/core/upload/admin/src/components/MediaLibraryInput/index.js#L33
- WEB https://grimthereaperteam.medium.com/strapi-v4-1-12-unrestricted-file-upload-b993bfd07e4e
Ready to move
Start Securing
Free, no credit card | First findings in minutes