GHSA-m47h-25hm-c3r9HighCVSS 8.8
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended...
🔗 CVE IDs covered (1)
📋 Description
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.