Impact
Ghost, an open‑source publishing platform, contains an input validation flaw in its comment like feature. An authenticated member can delete comment likes or dislikes belonging to other users, bypassing the intended authorization controls. This unauthorized modification allows the attacker to alter comment engagement data, potentially skewing analytics or user experience.
Affected Systems
The affected product is Ghost published by TryGhost. Versions from 5.9.0 up through 6.44.0 are vulnerable; all releases 6.44.1 and newer include the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high severity. Evidence of exploitation is not documented (EPSS is unavailable) and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a locally authenticated user. An attacker needs valid credentials with commenting permissions but does not require elevated privileges; the data modification does not grant control over the system as a whole, yet permits changing observable engagement metrics.
OpenCVE Enrichment