Junglewise Threat Intelligence

CVE-2023-30843: Payload CMS information disclosure via hidden field brute force

CVE-2023-30843 · Severity: low · CVSS 3.1 · Published 2023-04-26

Technologies: payload (npm). Vendors: npm.

Executive brief

Payload is an open-source content management system (CMS) used to manage website and application data. A security flaw allowed unauthorized users to potentially discover sensitive information stored in 'hidden' fields that they should not be able to see. By sending specifically crafted search queries, an attacker could use trial-and-error (brute force) to reveal private data, potentially leading to the exposure of internal system details or customer information.

Technical details

A vulnerability in Payload CMS versions prior to 1.7.0 allows for the exposure of sensitive information through the query engine. While certain fields may be marked as hidden or restricted via access control, the 'where' query logic did not sufficiently isolate these fields from being used as filter criteria. An attacker with read access to a collection can execute brute-force 'where' queries to systematically guess and confirm the values of hidden fields based on whether the query returns a result. This is classified as CWE-200 (Exposure of Sensitive Information). The issue is resolved in version 1.7.0; a workaround involves implementing a 'beforeOperation' hook to sanitize 'where' queries that target restricted fields.

Affected products

  • payloadcms payload < 1.7.0

Timeline

  • 2023-04-18: patched: Version 1.7.0 released
  • 2023-04-26: disclosed: GitHub Security Advisory published

References

Related threats