Impact
Ghost from version 0.8.0 through 6.22.x contains an information disclosure flaw. The setup endpoint, which should be secured or removed, will return the site owner's email address to anyone who sends an unauthenticated request. An attacker can use the returned email address for targeted phishing, social engineering, or as a reconnaissance step for further attacks. The vulnerability does not provide code execution or direct access to data, but it compromises the confidentiality of the site owner's contact information.
Affected Systems
The affected product is Ghost, maintained by TryGhost. Vulnerable releases include Ghost 0.8.0 up to, but not including, version 6.23.0. Systems running any version in this range expose the email address via the setup endpoint.
Risk and Exploitability
The CVSS score of 6.9 classifies this issue as a medium severity flaw. The EPSS score is not available, so the likelihood of exploitation in the wild cannot be precisely measured, but the vulnerability is publicly documented and the impacted endpoint is reachable over the network. The flaw is listed as not in the CISA KEV catalog, indicating no known active exploitation at the time of the analysis. Attackers can obtain the disclosed email address by crafting simple HTTP requests to the setup endpoint without authentication, making the exploit trivial for automated scanners or custom scripts.
OpenCVE Enrichment