logo

Database

Insecure file upload In payload

Description

Payload: Uploaded XML files could execute same-origin JavaScript

Impact

Under certain local upload configurations, an uploaded XML file and stylesheet could execute JavaScript in the Payload origin when a logged-in user opens the file.

You are affected if:

    You accept XML uploads (accepted by default).

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Disallow XML/XSL uploads.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions