{"id":"GHSA-37hx-4mcq-wc3h","summary":"Weak Password Recovery Mechanism for Forgotten Password in Strapi","details":"In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.","aliases":["CVE-2021-28128"],"modified":"2023-11-08T04:05:28.524574Z","published":"2021-10-06T17:48:16Z","database_specific":{"nvd_published_at":"2021-05-06T14:15:00Z","cwe_ids":["CWE-640"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-10-06T14:09:30Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28128"},{"type":"WEB","url":"https://github.com/strapi/strapi/issues/9657"},{"type":"PACKAGE","url":"https://github.com/strapi/strapi"},{"type":"WEB","url":"https://github.com/strapi/strapi/releases/tag/v3.6.0"},{"type":"WEB","url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-008.txt"}],"affected":[{"package":{"name":"strapi","ecosystem":"npm","purl":"pkg:npm/strapi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"3.6.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-37hx-4mcq-wc3h/GHSA-37hx-4mcq-wc3h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}