First published: Thu May 06 2021(Updated: )
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Strapi Strapi | <=3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-28128 is high with a CVSS score of 8.1.
CVE-2021-28128 allows an attacker with a valid session to change an account's password without entering the current password, potentially leading to account takeover.
Versions up to and including 3.6.0 of Strapi are affected by CVE-2021-28128.
Upgrade to a version of Strapi newer than 3.6.0 to fix CVE-2021-28128.
More information about CVE-2021-28128 can be found at the following references: [1] [2] [3]