PT-2023-22998 · Pyload · Pyload
Cpaczek
·
Published
2023-04-26
·
Updated
2023-05-05
·
CVE-2023-30843
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Payload versions prior to 1.7.0
Description
The issue allows a user to reverse-engineer hidden field values via brute force if they have access to documents containing these fields. This can be done by attempting to access hidden field data through
where queries.Recommendations
For versions prior to 1.7.0, update to version 1.7.0 to resolve the issue.
As a temporary workaround for versions prior to 1.7.0, consider writing a
beforeOperation hook to remove where queries that attempt to access hidden field data.
Monitor your instance for brute-force style requests against your instance using where queries to detect potential compromise.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyload