CVE-2020-27665
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
HIGH · CVSS 7.5
EPSS 0.00292
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0