CVE-2023-22894

MEDIUM CISA KEV POC Pub 19/04 Upd 09/10

Overview

This vulnerability is an information disclosure flaw arising from improper access control in Strapi's admin panel query filtering mechanism. The root cause lies in the ability to filter user data by columns containing sensitive information without adequate validation or restriction. The affected component is the Strapi admin panel's user query API, which processes filter parameters allowing unauthorized inference of protected user attributes.

Vulnerability Description

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.

Impact

An attacker with access to the Strapi admin panel can leverage this vulnerability to enumerate sensitive user information. Super admin users can retrieve password hashes and reset tokens for all users, facilitating credential compromise. Admin users with restricted permissions can access usernames and emails of API users with lower roles, enabling targeted phishing or further attacks. This leads to significant data breaches and potential lateral movement within affected environments.

Solution

Upgrade Strapi to version 4.5.6 or later, where this vulnerability is addressed as documented in the Strapi security disclosure (https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve). Review the official GitHub release notes at https://github.com/strapi/strapi/releases for patch details. No specific workarounds are provided; applying the vendor patch is required to remediate the issue.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (1)

Vendor Product Version CPE
strapi Strapi Strapi All cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (2)

Repository Author Stars Forks Date Link
Saboor-Hakimi/CVE-2023-22894
CVE-2023-22894
Saboor-Hakimi 13 2 2023-04-24 View
maxntv/CVE-2023-22894-PoC
maxntv 0 0 2025-07-31 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

5 events
2026-10-09
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-10-08
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-10-08
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2023-04-24
PoC Published (2 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Detected as Exploited in the Wild (233 sightings)

Active exploitation confirmed with 233 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Information Disclosure
94% info_disclosure
Insecure Direct Object Reference
77% idor
Authentication Bypass
74% auth_bypass
Authorization Bypass
64% authz_bypass

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-37 Retrieve Embedded Sensitive Data
30%
High Very High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (5)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2023-22894
github.com
GitHub CVE
https://github.com/strapi/strapi/releases
ghostccamm.com
GitHub CVE
https://www.ghostccamm.com/blog/multi_strapi_vulns/
strapi.io
GitHub CVE
https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve
cisa.gov
NVD API
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22894