Medium severity4.8NVD Advisory· Published Jun 13, 2022· Updated Jun 17, 2026
CVE-2022-29894
CVE-2022-29894
Description
Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
strapinpm | <= 3.6.10 | — |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-mcqm-6ff4-53qxghsaADVISORY
- jvn.jp/en/jp/JVN44550983/index.htmlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-29894ghsaADVISORY
- strapi.ionvdVendor Advisory
- strapi.ioghsaWEB
News mentions
0No linked articles in our index yet.