Home
CRITICAL: 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L >= 3.24.0, < 6.19.1
affected
Description
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
References
github.com/.../Ghost/security/advisories/GHSA-w52v-v783-gw97
github.com/...ommit/30868d632b2252b638bc8a4c8ebf73964592ed91
github.com/TryGhost/Ghost/releases/tag/v6.19.1