Authentication mechanism absence or evasion In payload
Description
Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | - | ||
npm | 4.0.0-internal.f05c47f |
Aliases
1. 2. 3. 4.
References
1.