Improper Authorization in Strapi
High severity
GitHub Reviewed
Published
Oct 29, 2020
to the GitHub Advisory Database
•
Updated Sep 13, 2023
Description
Reviewed
Oct 29, 2020
Published to the GitHub Advisory Database
Oct 29, 2020
Last updated
Sep 13, 2023
In Strapi before 3.2.5, there is no
admin::hasPermissions
restriction for CTB (aka content-type-builder) routes.References