CVE-2022-41654
22.12.2022, 10:15
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
ghost | ghost | 4.46.0 ≤ 𝑥 < 4.48.8 |
ghost | ghost | 5.0.0 ≤ 𝑥 < 5.22.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration