GHSA-v575-g66p-vj84MediumCVSS 5.3
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypass extension validation and access sensitive theme files.