MEDIUM
GHSA-jg8r-5jh2-v2xj
Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts
Details
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/payload
Introduced in:
0No fixed version published yet for payload (npm). Pin to a known-safe version or switch to an alternative.