Impact
Ghost versions 5.8.0 through 6.33.99 contain an input validation vulnerability in the admin iframe that enables attackers with content publishing privileges to create malicious pages. When a staff user visits such a crafted page, the iframe can be manipulated to take over the staff account, compromising the user's credentials and any associated privileges. The flaw is rooted in CWE‑23, a Path Traversal weakness in input handling that allows attackers to hijack authenticated sessions. This leads to full account compromise, potentially exposing sensitive content, administrative controls, and other staff users.
Affected Systems
The affected products are TryGhost Ghost running any version earlier than 6.34.0, specifically from 5.8.0 up to 6.33.99. Users deploying Ghost on these releases should verify their version against the vendor’s release notes and ensure it is not included in the vulnerable range.
Risk and Exploitability
The vulnerability has a CVSS score of 8.5, indicating high severity. EPSS data is not available, so the attack probability cannot be quantified, and it has not been listed in the CISA KEV catalog. Attackers must have the ability to publish content within Ghost or otherwise send malicious links to staff users, implying the threat is limited to environments where the attacker can control published content or phish staff members. If such conditions exist, the risk is significant and the vulnerability is exploitable without requiring user interaction beyond visiting a crafted page.
OpenCVE Enrichment