Friday, December 23, 2022

Two New Security Flaws Reported in Ghost CMS Blogging Software

Cybersecurity researchers have detailed two security flaws in the JavaScript-based blogging platform known as Ghost, one of which could be abused to elevate privileges via specially crafted HTTP requests. Tracked as CVE-2022-41654 (CVSS score: 8.5), the authentication bypass vulnerability allows unprivileged users (i.e., members) to make unauthorized modifications to newsletter settings. Cisco
http://dlvr.it/SfqTWD

No comments:

Post a Comment

China APT Stole Geopolitical Secrets From Middle East, Africa & Asia - Dark Reading

China APT Stole Geopolitical Secrets From Middle East, Africa & Asia  Dark Reading http://dlvr.it/T7NsNm