Impact
Payload Plugins version 0.7.0 contains a plugin called payload‑alt‑text‑plugin that exposes two POST endpoints: /api/alt‑text‑plugin/generate and /api/alt‑text‑plugin/bulk. These endpoints are protected by a generic guard that accepts any authenticated user, and the handlers call req.payload.findByID and req.payload.update without setting overrideAccess to false. Because overrideAccess defaults to true, the handlers bypass the target collection’s read and update access checks, allowing an authenticated low‑privilege user to supply an id, collection name, locale, and new values in the request body to read and modify any protected upload document’s alt and keywords fields, even when the collection is configured to permit those operations only for administrators. A local API call that sets overrideAccess to false is correctly denied, confirming that the plugin endpoint is the source of the bypass. The vulnerability is addressed in alt‑text‑plugin version 0.8.0.
Affected Systems
The vulnerability affects the JHB Software Payload Plugins, specifically the payload‑alt‑text‑plugin submodule. The issue is present in version 0.7.0 of the plugin and is fixed in version 0.8.0. No other affected versions are reported in the input.
Risk and Exploitability
The CVSS score of 7.1 indicates medium to high severity, and the EPSS score is < 1 %, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. However, because the flaw can be leveraged by any authenticated user and the bypass requires only normal POST calls to the plugin endpoints, the likelihood of exploitation is non‑negligible in environments where the plugin is enabled and lower‑privilege users exist. Once exploited, the attacker can read and tamper with protected documents, potentially compromising the confidentiality and integrity of content.
OpenCVE Enrichment
Github GHSA