Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wj4w-mc24-pcfm

Опубликовано: 01 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

EPSS

Процентиль: 9%
0.00203
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
2 дня назад

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

CVSS3: 6.5
debian
2 дня назад

Ghost, an open-source publishing platform, contains an input validatio ...

EPSS

Процентиль: 9%
0.00203
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-639