Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.
Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.