Strapi through version 4.5.5 permits authenticated administrative-panel users to use query filters against private or sensitive user-model fields. Response behavior can be used as an oracle to infer values held in those fields, despite the fields not being intended for disclosure. A super administrator can infer password hashes and password-reset tokens for administrative and API users. An administrator with access to lower-privileged API-user usernames and email addresses can infer sensitive data for those API users, but not for other administrative accounts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python exploit script (CVE-2023-22894.py) targeting Strapi CMS instances vulnerable to CVE-2023-22894. The script takes a target URL and a public Strapi endpoint as arguments. It then performs a brute-force attack by sending concurrent HTTP GET requests with crafted query parameters to enumerate the bcrypt password hash of a user, and optionally the password reset token. The script uses multithreading to speed up the brute-force process. The main entry point is the Python script itself, which is run from the command line. No hardcoded endpoints are present; the user must supply the vulnerable endpoint. The exploit is operational and demonstrates the vulnerability by extracting sensitive user information from the target Strapi instance.
This repository provides two Python proof-of-concept exploit scripts targeting Strapi CMS versions <=4.7.1, specifically exploiting CVE-2023-22894. The vulnerability allows attackers to leak sensitive information (password hashes and reset tokens) by abusing Strapi's filtering functionality on private fields. - `dump-auth.py` is an authenticated exploit requiring valid Strapi admin credentials. It logs in, retrieves an API token, and then enumerates admin and API user accounts to extract their password hashes and reset tokens via crafted API requests. - `dump-authless.py` is an unauthenticated exploit that targets public API endpoints with a relationship to the User model. It brute-forces and leaks password hashes and, optionally, password reset tokens without needing credentials, provided a suitable endpoint is exposed. Both scripts use multi-threading to speed up the brute-force process. The repository includes a detailed README explaining usage, prerequisites, and the vulnerability context. The main attack vector is network-based, targeting Strapi HTTP API endpoints. The scripts do not provide direct code execution but enable credential theft and account takeover, which can be chained with other vulnerabilities for further exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Strapi ORM Leak vulnerability that could expose administrator password-reset tokens and enable takeover of a Strapi instance.
An earlier Strapi vulnerability referenced because its patch could be bypassed by CVE-2023-34235.
A prior Strapi vulnerability that allowed filtering on private fields and exposed sensitive user data.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.