Impact
Ghost versions 6.20.0 up to but not including 6.57.1 contain a flaw in session management that lets any authenticated staff user log in as any other staff member by supplying only a password. This bypasses two‑factor authentication and permits the attacker to assume another staff member’s identity, thereby gaining access to administrative functions. The vulnerability is classified as CWE-613 – session fixation or authentication bypass. The CVSS score of 8.6 indicates substantial impact on confidentiality, integrity, and availability of the system.
Affected Systems
The affected systems are Ghost content management platforms released by TryGhost, specifically all versions from 6.20.0 through 6.56.x. Users running later versions are not impacted.
Risk and Exploitability
The high CVSS score reflects both the severity of the issue and the ease of exploitation once staff credentials are known. EPSS data is unavailable, but the lack of a list in CISA’s KEV catalog does not diminish the risk; attackers with valid staff credentials can abuse the flaw immediately. The likely attack vector requires the attacker to be an authenticated staff user, after which they can manipulate the session payload to impersonate other staff accounts.
OpenCVE Enrichment