PayloadCMS 的 @payloadcms/storage-vercel-blob 存储适配器存在一个不正确的访问控制漏洞,允许经过身份验证的用户通过直接访问 client-upload 路由绕过集合级别的权限限制。攻击者可以通过 client-upload 端点上传文件,而无需具备所需的集合访问权限,从而绕过预期的访问控制机制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| payloadcms | payload | 3.25.0< 3.90.0 |
affected |
4.0.0-canary.0< 4.0.0-canary.34 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | 3.25.0 ~ 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet