Description
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
Remediation
References
https://github.com/TryGhost/Ghost/security/advisories/GHSA-9gh8-wp53-ccc6
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1624
Related Vulnerabilities
CVE-2017-5662 Vulnerability in maven package org.eclipse.birt.runtime:org.apache.batik.dom
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2019-3888 Vulnerability in maven package io.undertow:undertow-core
CVE-2017-3589 Vulnerability in maven package mysql:mysql-connector-java
CVE-2022-29256 Vulnerability in maven package org.webjars.npm:sharp