GHSA-4vm8-j95f-j6v5
Dashboard / Vulnerabilities / GHSA-4vm8-j95f-j6v5
Summary: Strapi 4.1.12 Cross-site Scripting via crafted file
Details: An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted file. After an authenticated attacker uploads a file containing a malicious URL, a victim copies and pastes the malicious URL into a new tab to receive the XSS payload.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-32114, https://docs.strapi.io/dev-docs/configurations/public-assets, https://docs.strapi.io/user-docs/users-roles-permissions/configuring-administrator-roles, https://github.com/bypazs/strapi, https://github.com/strapi/strapi, https://github.com/strapi/strapi/blob/d9277d616b4478a3839e79e47330a4aaf167a2f1/packages/core/content-type-builder/admin/src/components/AllowedTypesSelect/index.js#L14, https://github.com/strapi/strapi/blob/d9277d616b4478a3839e79e47330a4aaf167a2f1/packages/core/upload/admin/src/components/MediaLibraryInput/index.js#L33, https://grimthereaperteam.medium.com/strapi-v4-1-12-unrestricted-file-upload-b993bfd07e4e
Affected packages
Package
Name: @strapi/strapi
Purl: pkg:npm/%40strapi/strapi
Affected ranges
Type: SEMVER
Events:
