CVE Database
/

CVE-2022-29894

Back to search

CVE-2022-29894

Published: Jun 13, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.

VendorProductVersions

Strapi

Strapi

affected
v3.x.x versions and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now