Executive brief
Strapi is a popular open-source headless CMS platform used by developers to build content management systems. This vulnerability allows unauthenticated attackers to upload arbitrary files and execute malicious code on the server, potentially compromising the entire system and customer data.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in Strapi's file upload module affecting version 4.1.5 and earlier. The vulnerability allows unauthenticated attackers to upload arbitrary files through a network request without authentication, enabling remote code execution on the affected system. The attack has no access control requirements and can be triggered directly over the network. Successful exploitation grants attackers complete control over the server, including the ability to read, modify, or delete data, and disrupt service availability. Patches are available in newer versions of Strapi.
Affected products
- Strapi Strapi 4.1.5 and earlier
Timeline
- 2022-04-13: disclosed
- 2022-04-22: advisory: GitHub advisory review