EN

high

Strapi: Cross-site scripting possible

CERT-Bund (BSI) reports one vulnerability in Strapi with severity high. The stated impact is cross-site scripting. The full description, affected versions and recommended action are available from CERT-Bund (BSI).

Attack vector
over the network
Access needed
yes, an account is needed

What this means for you

Attackers can run code in your users' browsers. This mainly affects publicly reachable portals and login forms, where sessions can be taken over.

Original source

CERT-Bund (BSI)

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.