Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x7gh-ph2w-vvr2

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.

EPSS

Процентиль: 11%
0.0021
Низкий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.1
nvd
8 дней назад

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.

CVSS3: 8.1
debian
8 дней назад

A broken access control vulnerability in Ghost Foundation Ghost 5.x al ...

EPSS

Процентиль: 11%
0.0021
Низкий

8.1 High

CVSS3

Дефекты

CWE-284