CVE-2025-4644
Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
29/08/2025
Última modificación:
29/08/2025
Descripción
*** Pendiente de traducción *** A Session Fixation vulnerability existed in Payload&#39;s SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and perform actions as that user.<br />
<br />
This issue has been fixed in version 3.44.0 of Payload.
Impacto
Puntuación base 4.0
5.30
Gravedad 4.0
MEDIA



