CVE-2023-22894
Overview
This vulnerability is an information disclosure flaw arising from improper access control in Strapi's admin panel query filtering mechanism. The root cause lies in the ability to filter user data by columns containing sensitive information without adequate validation or restriction. The affected component is the Strapi admin panel's user query API, which processes filter parameters allowing unauthorized inference of protected user attributes.
Vulnerability Description
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.
Impact
An attacker with access to the Strapi admin panel can leverage this vulnerability to enumerate sensitive user information. Super admin users can retrieve password hashes and reset tokens for all users, facilitating credential compromise. Admin users with restricted permissions can access usernames and emails of API users with lower roles, enabling targeted phishing or further attacks. This leads to significant data breaches and potential lateral movement within affected environments.
Solution
Upgrade Strapi to version 4.5.6 or later, where this vulnerability is addressed as documented in the Strapi security disclosure (https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve). Review the official GitHub release notes at https://github.com/strapi/strapi/releases for patch details. No specific workarounds are provided; applying the vendor patch is required to remediate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Strapi | Strapi | All |
cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Saboor-Hakimi/CVE-2023-22894
CVE-2023-22894
|
Saboor-Hakimi | 13 | 2 | 2023-04-24 | View |
|
maxntv/CVE-2023-22894-PoC
|
maxntv | 0 | 0 | 2025-07-31 | View |
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Active exploitation confirmed with 233 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-37 | Retrieve Embedded Sensitive Data |
30%
|
High | Very High |
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-22894 |
| github.com |
GitHub CVE
|
https://github.com/strapi/strapi/releases |
| ghostccamm.com |
GitHub CVE
|
https://www.ghostccamm.com/blog/multi_strapi_vulns/ |
| strapi.io |
GitHub CVE
|
https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22894 |