Authorization Flaw in Strapi Content-Type Builder Routes
CVE-2020-27665
7.5HIGH
What is CVE-2020-27665?
In versions of Strapi prior to 3.2.5, there exists an authorization flaw in the content-type-builder routes due to a lack of the admin::hasPermissions restriction. This could potentially allow unauthorized users to access sensitive routes, leading to severe security implications. Users and administrators should ensure they update to version 3.2.5 or later to mitigate this risk.
