CVE-2024-43409

CVSS V2 None CVSS V3 None
Description
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
Overview
  • CVE ID
  • CVE-2024-43409
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-20T15:05:04.338Z
  • Last Modified Date
  • 2024-08-20T15:05:04.338Z
History
Created Old Value New Value Data Type Notes
2024-08-21 13:19:07 Added to TrackCVE