Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery
A vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset. Users are affected if: They are using Payload version < v3.79.1 with any auth-enabled collection using the built-in forgot-password functionality.