Improper Neutralization of Special Elements in Data Query Logic in Ghost - #VU142534
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to modify comment like or dislike data they are not authorized to delete.
The vulnerability exists due to improper access control in the comment like feature when handling delete requests for comment likes or dislikes. A remote user can send a crafted request to modify comment like or dislike data they are not authorized to delete.