{"id":"GHSA-65wv-528r-m892","summary":"Improper Input Validation in strapi","details":"Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation. By sending a specially crafted request, an attacker could exploit this vulnerability to update the email template for both password reset and account confirmation emails.","aliases":["CVE-2020-13961"],"modified":"2023-11-08T04:02:24.509618Z","published":"2022-05-24T17:21:16Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-21T20:05:07Z","nvd_published_at":"2020-06-19T17:15:00Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13961"},{"type":"WEB","url":"https://github.com/strapi/strapi/pull/6599"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/183045"},{"type":"PACKAGE","url":"https://github.com/strapi/strapi"},{"type":"WEB","url":"https://github.com/strapi/strapi/releases/tag/v3.0.2"}],"affected":[{"package":{"name":"strapi","ecosystem":"npm","purl":"pkg:npm/strapi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-65wv-528r-m892/GHSA-65wv-528r-m892.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}