Impact
The vulnerability exists in Ghost’s post‑feedback component and allows an attacker to submit arbitrary feedback on behalf of authenticated members without their consent. The effect is to create or alter content that appears to come from legitimate users, which can be used for defacement, spreading misinformation, or tampering with user reputation. The weakness is a classic CSRF flaw, as identified by CWE‑352.
Affected Systems
Ghost content management system versions 5.19.0 through 6.57.0 are affected. The vulnerability is present in the core feedback module regardless of the site’s configuration, so any Ghost installation that has the feedback functionality enabled and is behind a user login is in scope.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact with effects limited to the confidentiality and integrity of user content. Because the attack requires a victim to be authenticated and to visit a crafted link, the practical exploitation window is narrower and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread public exploitation has been reported. Nonetheless, an attacker can automate traffic to the feedback endpoint by hosting a malicious URL, and the impact could scale with the number of authenticated users targeted. Prompt remediation is advised to prevent potential abuse.
OpenCVE Enrichment