CVE-2022-30618 is a high-severity vulnerability affecting Strapi, where an authenticated admin panel user can view sensitive API user data, including email and password reset tokens, if content types have relationships to API users. This flaw allows for account compromise, potentially escalating privileges from a low-privileged user to a high-privileged API account, enabling data manipulation and denial of service. The vulnerability has a CVSS score of 7.5 (High) due to its network attack vector, high impact on confidentiality, integrity, and availability, but requires high attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.6.10CPE matchmatch criteria | cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.1.10CPE matchmatch criteria | cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.