PT-2024-30566 · Ghost · Ghost

1337Nerd

·

Published

2024-08-20

·

Updated

2025-07-29

·

CVE-2024-43409

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ghost versions 4.46.0 through 5.89.4
Description The issue is related to improper authentication on some endpoints used for member actions, allowing an attacker to perform member-only actions and read member information.
Recommendations For Ghost versions 4.46.0 through 5.89.4, update to version 5.89.5 to resolve the issue. As a temporary workaround, consider disabling site membership in Ghost settings until the update is applied.

Exploit

Fix

Improper Access Control

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-GHOST-2024-43409
CVE-2024-43409
GHSA-78X2-CWP9-5J42

Affected Products

Ghost