Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in Strapi's content management system, specifically within the rich text editor's preview function. This issue allows an authenticated user with author privileges to inject malicious scripts that could execute within the sessions of higher-privileged users, potentially leading to account takeover. The primary concern is confirming whether this specific functionality is in use and exposed to such a risk.
- Malicious scripts can run in privileged user sessions.
- Impacts administrators through content previews.
- Confirm relevance and exposure within the environment.
Attack Path
How an attacker could exploit the issue
An attacker with author privileges can inject malicious script tags into rich text fields within Strapi's content manager. When an administrator views the preview of this rich text content, the injected scripts execute within their browser session, potentially leading to account takeover.
- Requires author role access.
- Triggered by previewing rich text.
- Risk of administrative account takeover.
Live Threat
Current exploitation, exposure, and threat context
A stored cross-site scripting vulnerability in the Strapi content manager's WYSIWYG preview component could allow an authenticated 'Author' user to execute arbitrary script code in the browser of an 'Editor' or 'Super Admin' user when they interact with the preview pane. This could potentially lead to account takeover.
- Stored script tags in rich text fields.
- Malicious scripts execute in admin session.
- Account takeover of admin user.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and infrastructure teams are primarily responsible for addressing this stored cross-site scripting vulnerability in Strapi. The first practical step is to identify all Strapi instances, confirm their exposure and criticality, and then locate the accountable owner to plan remediation.
- Identify Strapi owners and critical instances.
- Verify WYSIWYG preview component reachability.
- Plan and coordinate remediation based on risk.