Описание
Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or its members. This issue is fixed in version 6.44.0.
Ссылки
EPSS
Процентиль: 17%
0.00257
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-472
Связанные уязвимости
CVSS3: 5.3
debian
28 дней назад
Ghost is a Node.js content management system. From 6.27.0 before 6.44. ...
CVSS3: 5.3
github
2 дня назад
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
EPSS
Процентиль: 17%
0.00257
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-472