Description
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2146 | In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password. |
Github GHSA |
GHSA-37hx-4mcq-wc3h | Weak Password Recovery Mechanism for Forgotten Password in Strapi |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:33:17.461Z
Reserved: 2021-03-10T00:00:00.000Z
Link: CVE-2021-28128
No data.
Status : Modified
Published: 2021-05-06T14:15:08.417
Modified: 2024-11-21T05:59:08.400
Link: CVE-2021-28128
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA