CyberRota Analysis
AI-GeneratedStrapi versions 4.x through 4.26.2 and 5.x before 5.48.1 are vulnerable to a stored cross-site scripting (XSS) flaw in the WYSIWYG preview component, allowing Author-role users to inject malicious script tags into rich text fields. This vulnerability can lead to the execution of scripts in the sessions of Editors or Super Admins, potentially resulting in account takeover. Organizations using affected Strapi versions should prioritize immediate updates to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.