Improper access control in strapi - CVE-2024-56143
Published: April 23, 2026
strapi
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the parms.lookup query operator when processing lookup filter parameters for private fields. A remote attacker can send a specially crafted lookup query to disclose sensitive information.
The issue can be used to perform filtering attacks against private fields, including admin passwords and reset tokens.