Improper access control in strapi - CVE-2023-37263
Published: September 13, 2023 / Updated: April 23, 2026
strapi
strapi.io
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the relationship title handling in @strapi/plugin-content-manager when handling relation endpoint responses. A remote privileged user can access a relationship field configured as the title to disclose sensitive information.
User interaction is required to view the affected content in the content manager.