Description
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7303 | An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability. |
Github GHSA |
GHSA-9gh8-wp53-ccc6 | ghost vulnerable to unauthorized newsletter modification via improper access controls |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-04-14T18:08:15.772Z
Reserved: 2022-09-29T00:00:00.000Z
Link: CVE-2022-41654
Updated: 2024-08-03T12:49:43.405Z
Status : Modified
Published: 2022-12-22T10:15:10.047
Modified: 2024-11-21T07:23:34.413
Link: CVE-2022-41654
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA