Description
If a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values via brute force.
Affected versions: < 1.7.0
Recommendation
Update the payload package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.7.0
- Patched version(s): 1.7.0
References
Related Issues
- tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload - CVE-2022-25854
- Leaking sensitive user information still possible by filtering on private with prefix fields (GHSA-9xg4-3qfm-9w8f) - CVE-2023-34235
- Leaking sensitive user information still possible by filtering on private with prefix fields - CVE-2023-34235
- Unauthorized Access to Private Fields in User Registration API (GHSA-gc7p-j5xm-xxh2) - CVE-2023-39345
- Tags:
- npm
- payload
Anything's wrong? Let us know Last updated on November 11, 2023