Impact
Ghost versions before 6.62.0 have an authentication bypass that lets a suspended staff user reset their password and reactivate the account. The attacker regains original privileges, providing a path to full control of the site. The flaw is a classic authentication bypass (CWE-862).
Affected Systems
TryGhost's Ghost content management system, all releases prior to 6.62.0, including Ghost 1.0.0 through 6.61.x, is affected. The vulnerability resides in the self‑service password‑reset flow for suspended staff accounts.
Risk and Exploitability
The CVSS score of 8.7 indicates high impact. No EPSS data is available, but the flaw can be exploited via the public password‑reset interface, so remote attackers can use the flaw if they have evidence of a suspended staff credential. The vulnerability is not listed in the CISA KEV catalog, but its high severity means it should be treated as a high‑priority risk.
OpenCVE Enrichment