VDB
Sign up
MEDIUM

GHSA-jg8r-5jh2-v2xj

Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts

Details

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/payload
Introduced in: 0

No fixed version published yet for payload (npm). Pin to a known-safe version or switch to an alternative.

References