CVE-2022-41654: Critical severity ghost ghost node.js vulnerability
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-41654.
What is the severity of CVE-2022-41654?
The severity of CVE-2022-41654 is critical.
What is the affected software?
The affected software is Ghost Foundation Ghost 5.9.4.
How can an attacker exploit CVE-2022-41654?
An attacker can exploit CVE-2022-41654 by sending a specially-crafted HTTP request to the newsletter subscription functionality of Ghost.
Are there any references for CVE-2022-41654?
Yes, you can find references for CVE-2022-41654 at the following links: [link1](https://github.com/TryGhost/Ghost/security/advisories/GHSA-9gh8-wp53-ccc6) and [link2](https://talosintelligence.com/vulnerability_reports/TALOS-2022-1624).