Impact
Ghost versions from 3.10.0 up to 6.33.9 do not completely invalidate session data after a password change, enabling an attacker who has obtained a session cookie to continue accessing the user account even after a password reset. This flaw allows persistent unauthorized access and threatens confidentiality and integrity of user data by permitting attackers to maintain footholds in compromised accounts. The weakness is a classic session invalidation bypass, classified as CWE‑613.
Affected Systems
The affected product is Ghost content management system from vendor TryGhost. Versions starting with 3.10.0 and older than 6.34.0 are vulnerable; any installations using 3.10.0 through 6.33.9 are at risk.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity impact. The EPSS score is not available, so the current probability of exploitation cannot be quantified, but the flaw is in the session management layer, which is typically accessible via HTTP. Because the vulnerability does not require privileged access to exploit, attackers with reasonable network visibility or those who have stolen a session cookie can actively abuse it. The issue is not listed in the CISA KEV catalog, but it remains a serious risk for sites that rely on Ghost for user authentication. The likely attack vector is a stolen or intercepted session cookie combined with a password reset mechanism that does not clear all session identifiers.
OpenCVE Enrichment