Loading
Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.
Use CWE-918, Strapi vendor hub and Strapi product page to widen CVE-2024-52588 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-37818, CVE-2024-56143 and CVE-2023-39345 for nearby disclosures in the same product family.