CVE-2023-22894
CWE-312
Raised to High: in CISA KEV (known exploited)
63.6
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.
Source: NVD
Signals
- CVSS
- 4.9
- Medium · v3.1
- EPSS
- 1.65%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Oct 2026
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-312
- Published
- 19 Apr 2023
- Last modified 8 Oct 2026
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-22894Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 9 Oct 2026, 05:16 UK time