CVE-2022-29894
Summary
| CVE | CVE-2022-29894 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-13 05:15:00 UTC |
| Updated | 2022-06-22 12:12:00 UTC |
| Description | Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#44550983: Strapi vulnerable to cross-site scripting | MISC | jvn.jp | |
| GitHub - strapi/strapi: ???? Open source Node.js Headless CMS to easily build customisable APIs | MISC | github.com | |
| strapi.io | MISC | strapi.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.