{"id":"CVE-2019-18818","aliases":["GHSA-6xc2-mj39-q599"],"url":"https://o3.security/vulnerability/CVE-2019-18818","summary":"Strapi allows unauthenticated attacker to reset admin password without valid reset token","details":"strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.","published":"2019-11-07T22:15:10.570Z","modified":"2026-07-08T05:56:04.402101807Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.97639,"percentile":0.99899,"asOf":"2026-09-05"},"cisaKev":null,"exploitsKnown":8,"affectedPackages":[{"ecosystem":"npm","name":"strapi","fixedVersion":"3.0.0-beta.17.5"}],"fix":{"url":"https://github.com/strapi/strapi/pull/4443","label":"strapi/strapi#4443"},"references":[{"type":"ADVISORY","url":"https://github.com/strapi/strapi/pull/4443"},{"type":"ADVISORY","url":"https://github.com/strapi/strapi/releases/tag/v3.0.0-beta.17.5"},{"type":"ADVISORY","url":"https://www.npmjs.com/advisories/1311"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/163939/Strapi-3.0.0-beta-Authentication-Bypass.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/163950/Strapi-CMS-3.0.0-beta.17.4-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165896/Strapi-CMS-3.0.0-beta.17.4-Privilege-Escalation.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:56:04.402101807Z"}}