{ads}

Two New Security Flaws Reported in Ghost CMS Blogging Software



December 22, 2022 at 03:39PM

Cybersecurity researchers have detailed two security flaws in the JavaScript-based blogging platform known as Ghost, one of which could be abused to elevate privileges via specially crafted HTTP requests. Tracked as CVE-2022-41654 (CVSS score: 8.5), the authentication bypass vulnerability that allows unprivileged users (i.e., members) to make unauthorized modifications to newsletter settings.

from The Hacker News https://ift.tt/Q4K8AXy

0 Response to "Two New Security Flaws Reported in Ghost CMS Blogging Software"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads