CVE-2022-32114

🟠 Łataj w tym tygodniu

Nieograniczony upload plików w Strapi umożliwia ataki XSS przez złośliwy plik PDF.

CVSS
8.8
EPSS
1.6%
Exploit
poc
Vendor
strapi
Opis źródłowy (NVD)

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be able to upload PDF files containing JavaScript, and that all files in a public assets folder are accessible to the outside world (unless the filename begins with a dot character). The administrator can choose to allow only image, video, and audio files (i.e., not PDF) if desired.

exploit xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.6%
Opublikowano (NVD)2022-07-13 21:15:08 UTC
Ostatnia modyfikacja (NVD)2026-07-02 16:00:48 UTC
Referencje