National Cyber Warfare Foundation (NCWF)

CVE-2024-29181


0 user ratings
2024-03-18 00:00:00
milo
CVEs

 - archive -- 

CVE-2024-29181

Date: 2024-03-18

CVE Link

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.



References:



Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.