Vulnerabilities/

@strapi/plugin-content-manager leaks data via relations via the Admin Panel

Severity:
Low

Description

  1. If a super admin creates a collection where an item in the collection has an association to another collection, a user with the Author Role can see the list of associated items they did not create. They should only see their own items that they created, not all items ever created.

Recommendation

Update the @strapi/plugin-content-manager package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@strapi/plugin-content-manager
Anything's wrong? Let us know Last updated on June 14, 2024

This issue is available in SmartScanner Professional

See Pricing