Description
Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.
Remediation
References
https://github.com/strapi/strapi
https://jvn.jp/en/jp/JVN44550983/index.html
https://strapi.io/
Related Vulnerabilities
CVE-2021-32769 Vulnerability in maven package io.micronaut:micronaut-core
CVE-2019-10390 Vulnerability in maven package com.splunk.splunkins:splunk-devops
CVE-2022-28156 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest
CVE-2017-15680 Vulnerability in maven package org.craftercms:crafter-studio