CVE-2020-27665

Publication date

2020-10-22 18:19:31

Family

mitre

State

PUBLISHED

Description

In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.