SB2023091375 - Improper access control in strapi
Published: September 13, 2023 Updated: April 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2023-36472)
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the /content-manager/relations route when handling relation field selection in content-manager views. A remote user can select private fields and access user reset password tokens to disclose sensitive information.
User interaction is required, and exploitation requires configure view permissions.
Remediation
Install update from vendor's website.