VYPR
High severity8.1NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026

CVE-2021-28128

CVE-2021-28128

Description

In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
strapinpm
<= 3.6.0

Affected products

3
  • Strapi/Strapidescription
  • ghsa-coords
    Range: <= 3.6.0
  • cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*
    Range: <=3.6.0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.