Description
If a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values via brute force.
Affected versions: < 1.7.0
Recommendation
Update the payload
package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.7.0
- Patched version(s): 1.7.0
References
Related Issues
- Payload's SQLite adapter Session Fixation vulnerability (GHSA-26rv-h2hf-3fw4) 2 - CVE-2025-4644
- Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24772
- Remote Code Execution on click of <a> Link in markdown preview - CVE-2024-49362
- XSS vulnerability that affects bootstrap (GHSA-3mgp-fx93-9xv5) - CVE-2018-20676
- Tags:
- npm
- payload
Anything's wrong? Let us know Last updated on November 11, 2023