Skip to content

Authentication bypass and enumeration vulnerabilities in Ghost CMS

  • by

CVE-2022-41654 allows external users to update their newsletter preferences too liberally, which could allow a user full access to create and modify newsletters, including the default sent to all members. 

Read More  Cyware News – Latest Cyber News