An attacker who has read plus create or update access to a collection can submit a request that includes a SQL injection targeting a specific field path shape and operators in Payload's SQLite and Postgres.
// you are affected if:- You use @payloadcms/db-sqlite or @payloadcms/db-d1-sqlite.
- You use @payloadcms/db-postgres or @payloadcms/db-vercel-postgres < 3.73.0.
- A readable collection has a json field, or a blocks field with blocksAsJSON: true.
- The attacker has read plus create or update access on it.
- You have no json or blocksAsJSON fields. richText is not affected.
- You run a patched version.
The patched version sanitizes the query input to prevent injection.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- Low
- User interaction
- None
- Confidentiality (vulnerable system)
- High
- Integrity (vulnerable system)
- High
- Availability (vulnerable system)
- None
- Confidentiality (subsequent systems)
- None
- Integrity (subsequent systems)
- None
- Availability (subsequent systems)
- None