Insecure Password Storage in Strapi Documentation Plugin
CVE-2021-46440
7.5HIGH
What is CVE-2021-46440?
The Strapi Documentation plugin prior to versions 3.6.9 and 4.1.5 contains a vulnerability that permits the storage of passwords in a recoverable format. This flaw allows an attacker to exploit HTTP requests to obtain a victim's cookie, decode it using base64, and extract the cleartext password. This not only compromises user data but also potentially enables further API attacks due to unauthorized access to sensitive API documentation.
