Strapi 4.1.12 Cross-site Scripting via crafted file
Moderate severity
GitHub Reviewed
Published
Jul 14, 2022
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Jul 13, 2022
Published to the GitHub Advisory Database
Jul 14, 2022
Reviewed
Aug 6, 2022
Last updated
Mar 21, 2024
An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted file. After an authenticated attacker uploads a file containing a malicious URL, a victim copies and pastes the malicious URL into a new tab to receive the XSS payload.
References