Impact
The vulnerability is an information disclosure flaw located in the Admin Feedback endpoint of Ghost. A staff user who is authorized to access the admin area can query the endpoint and retrieve sensitive member data because the endpoint lacks proper authorization checks.
Affected Systems
Affected systems include any installation of Ghost version 5.125.1 through 6.56. The product is the Ghost content management system, maintained by TryGhost.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog, suggesting it is not widely exploited. Because the attack requires staff privileges, the risk is primarily internal; however, if an attacker escalates privileges or gains staff credentials they could exfiltrate member information.
OpenCVE Enrichment