MEDIUM 4.6 npm

Strapi 4.1.12 Cross-site Scripting via crafted file

GHSA-4vm8-j95f-j6v5 · CVE-2022-32114

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted file. After an authenticated attacker uploads a file containing a malicious URL, a victim copies and pastes the malicious URL into a new tab to receive the XSS payload.

Ready to move

Start Securing

Free, no credit card | First findings in minutes