Количество 3
Количество 3
CVE-2026-103283
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
CVE-2026-103283
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnera ...
GHSA-xwp3-2mhg-j9rp
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-103283 Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions. | CVSS3: 8.1 | 0% Низкий | 2 дня назад | |
CVE-2026-103283 Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnera ... | CVSS3: 8.1 | 0% Низкий | 2 дня назад | |
GHSA-xwp3-2mhg-j9rp Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions. | CVSS3: 8.1 | 0% Низкий | 2 дня назад |
Уязвимостей на страницу