CVE-2019-18818 – Strapi / Strapi – Unspecified

CVE-2019-18818 is an unspecified vulnerability impacting multiple versions of Strapi. An exploit was observed in open source and a link to an exploit was shared in the underground.

Summary:

CVE-2019-18818 is an unspecified vulnerability impacting multiple versions of Strapi. An exploit was observed in open source and a link to an exploit was shared in the underground.

PoC Links(if available):

Packet Storm exploit –
https://packetstormsecurity.com/files/163939/Strapi-3.0.0-beta-Authentication-Bypass.html

Known Counter Measures:

The vendor addressed the vulnerability in Strapi version 3.0.0-beta.17.5.

Links to patches(if available)

https://github.com/strapi/strapi/releases/tag/v3.0.0-beta.17.5