{"id":"CVE-2021-28128","aliases":["GHSA-37hx-4mcq-wc3h"],"url":"https://o3.security/vulnerability/CVE-2021-28128","summary":"Weak Password Recovery Mechanism for Forgotten Password in Strapi","details":"In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.","published":"2021-05-06T14:15:08.417Z","modified":"2026-07-09T00:13:42.883143Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"strapi","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/strapi/strapi/releases"},{"type":"ADVISORY","url":"https://strapi.io/changelog"},{"type":"EVIDENCE","url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-008.txt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:13:42.883143Z"}}