Vulnerabilities/

Strapi mishandles hidden attributes within admin API responses

Severity:
High

Description

Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

Recommendation

Update the @strapi/strapi package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@strapi/strapi
Anything's wrong? Let us know Last updated on February 02, 2023

This issue is available in SmartScanner Professional

See Pricing