CVE-2022-41654

An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*
cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 07:23

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de omisión de autenticación en la funcionalidad de suscripción al boletín de Ghost Foundation Ghost 5.9.4. Una solicitud HTTP especialmente manipulada puede generar mayores privilegios. Un atacante puede enviar una solicitud HTTP para desencadenar esta vulnerabilidad.
References () https://github.com/TryGhost/Ghost/security/advisories/GHSA-9gh8-wp53-ccc6 - Third Party Advisory () https://github.com/TryGhost/Ghost/security/advisories/GHSA-9gh8-wp53-ccc6 - Third Party Advisory
References () https://talosintelligence.com/vulnerability_reports/TALOS-2022-1624 - Exploit, Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2022-1624 - Exploit, Third Party Advisory

Information

Published : 2022-12-22 10:15

Updated : 2024-11-21 07:23


NVD link : CVE-2022-41654

Mitre link : CVE-2022-41654

CVE.ORG link : CVE-2022-41654


JSON object : View

Products Affected

ghost

  • ghost
CWE
CWE-284

Improper Access Control