news.mlab.sh
Back to the feed
threat-intel

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

High
Summary

A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to deploy ClickFix attack flows, targeting over 700 websites across various sectors. The campaign leverages stolen admin API keys to inject malicious JavaScript, ultimately tricking users into downloading malware. Despite the availability of a patch, many affected sites have not yet implemented the necessary updates, leaving them vulnerable.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.