Retour à la veille

CVE-2026-103274

Publié : 1 octobre 2026
Modifié : 1 octobre 2026
Lien officiel NVD
Score CVSS
5.3
MEDIUM

Description détaillée

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Références et Patchs