#VU128205 Improper Authentication in Ghost - CVE-2024-43409
Published: August 20, 2024 / Updated: April 27, 2026
Ghost
Ghost
Description
The vulnerability allows a remote attacker to read member information and perform member-only actions.
The vulnerability exists due to improper authentication in some endpoints used for member actions when handling requests. A remote attacker can send crafted requests to read member information and perform member-only actions.