First published: Thu Oct 22 2020(Updated: )
`admin/src/containers/InputModalStepperProvider/index.js` in Strapi before 3.2.5 has unwanted `/proxy?url=` functionality.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/strapi | <3.2.5 | 3.2.5 |
Strapi Strapi | <3.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2020-27664.
The severity of CVE-2020-27664 is critical with a CVSS score of 9.8.
The affected software version is Strapi before 3.2.5.
`admin/src/containers/InputModalStepperProvider/index.js` in Strapi before 3.2.5 has unwanted `/proxy?url=` functionality.
CVE-2020-27664 can be fixed by upgrading to Strapi version 3.2.5 or later.