CVE-2024-56143
⚠️ highSummary
Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin passwords and reset tokens, by crafting queries with the lookup parameter. This vulnerability is fixed in 5.5.2.
CVSS Score
8.2
High
EPSS Score
0.0
Exploit Probability
Published Date
2025-10-16
First Seen: 2026-01-05
📊 Relative Risk Intelligence
This CVE is High Risk - more severe than 79.6% of all 328,009 vulnerabilities in our database.
#66,785
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Oct 16, 2025
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by
CISA
Last Modified
2025-12-31
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE IDs (Weakness Types)