Input validation error in strapi - CVE-2019-19609
Published: December 6, 2019 / Updated: July 5, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the "installPlugin" and "uninstallPlugin" handler functions. A remote authenticated administrator can execute arbitrary code on the target system via the "execa" function.
Affected software
How to mitigate CVE-2019-19609
Links to Public Exploits and PoC-codes
- Exploit #10180 - Strapi-RCE (Exploit script showcasing a mixture of CVE-2019-18818 and CVE-2019-19609 for unauthenticated remote code execution in Strapi CMS.) (July 5, 2024)
- Exploit #8401 - CVE-2019-19609-EXPLOIT () (September 25, 2022)
- Exploit #7064 - Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated) (November 25, 2021)
- Exploit #7066 - Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated) (November 25, 2021)
- Exploit #6663 - CVE-2019-19609-EXPLOIT (Exploit for CVE-2019-19609 in Strapi (Remote Code Execution) ) (August 29, 2021)