Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has been patched in versions 5.130.6 and 6.11.0.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Ghost Ghost
cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*
|
5.90.0
|
5.130.6
|
|
Ghost Ghost
cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*
|
6.0.0
|
6.11.0
|