Impact
The flaw allows an authenticated user to trigger an external URL-based file upload that follows a redirect to a destination not verified as trusted. During the redirect, the original authentication data can be forwarded to the new host, potentially leaking a valid session to an unintended recipient. This exposes the attacker to the authenticated user's session and any privileges associated with it. The weakness is reflected in CWE-200 (Information Exposure) and CWE-346 (Untrusted Resource Redirect).
Affected Systems
Payload CMS by PayloadCMS, specifically the product named "payload". All releases greater than version 3.0.0 and up to, but not including, version 3.90.0 are affected.
Risk and Exploitability
With a CVSS score of 7.2, this vulnerability carries a moderate to high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, indicating that it has not yet been widely exploited. The likely attack path requires a legitimate authenticated session to initiate an upload of a file from an external URL that redirects to a hostile server. Attackers would need to control or know the redirect target to capture the authentication data; the exploitation does not require local privileges or code execution. Because the vulnerability hinges on redirect handling, it is harder to exploit than a simple injection flaw, but it can still provide an attacker with a legitimate session token if execution conditions are met.
OpenCVE Enrichment