CVE-2021-28128
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.
HIGH · CVSS 8.1
EPSS 0.00259
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0