Strapi exposed data, password reset to CMS users lacking proper privilege
The popular, headless CMS Strapi patched two vulnerabilities that allowed users with lower levels of privilege to see data only higher privileged users were cleared to see — including information allowing account takeover.
Source: scmagazine.com