<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Strapi on PhllapsNET</title>
    <link>https://www.phllaps.net/tags/strapi/</link>
    <description>Recent content in Strapi on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/tags/strapi/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Strapi Cleartext Storage of Sensitive Information Vulnerability</title>
      <link>https://www.phllaps.net/posts/strapi-cleartext-storage-of-sensitive-information-vulnerability/</link>
      <pubDate>Thu, 08 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/strapi-cleartext-storage-of-sensitive-information-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: MEDIUM — CVSS 4.9&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained…&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;4.9 (Medium)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-10-08) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Fixed in &lt;code&gt;4.8.0&lt;/code&gt;&lt;/strong&gt; — upgrade to this release or later.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2023-22894.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
