Synced 17 Jun 2026 22:27 UTC Account
← All products

CVE-2023-39345

HIGH severity · CVSS 7.6 · Improper authentication
7.6CVSS HIGH

Summary

strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in version 4.13.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Impact & exploitability

Attack vectorAdjacent
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactLow
Integrity impactHigh
Availability impactLow
Exploit probability (EPSS)0%

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.