Ghost CMS 5.9.4 contains a user enumeration vulnerability in the login functionality. The application reveals whether a user account exists through different error messages, allowing attackers to enumerate valid user accounts via specially-crafted HTTP requests.
id: CVE-2022-41697
info:
name: Ghost CMS - User Enumeration
author: ritikchaddha
severity: me
...