VYPR
High severity8.1NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026

CVE-2021-28128

CVE-2021-28128

Description

In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
strapinpm
<= 3.6.0—

Affected products

3
  • Strapi/Strapi2 versions
    cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*range: <=3.6.0
    • (no CPE)
  • ghsa-coords
    Range: <= 3.6.0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.