Impact
Ghost CMS incorrectly restricts staff role assignments, allowing a user with Editor or Super Editor role to assign those same or higher roles to other staff members, even though the user does not possess the permission to do so. The primary impact is the unauthorized elevation of privileges, which can enable an attacker to gain administrative or editorial control over the site, modify content, and potentially access sensitive data or configuration settings. This flaw falls under CWE‑269, Improper Privilege Management, and can lead to a moderate‑severity compromise of confidentiality, integrity, and availability within the affected system.
Affected Systems
The vulnerable product is Ghost, the open‑source blogging platform sold under TryGhost:Ghost. All releases from Ghost 0.5.0 through 6.63.9 (i.e., any version prior to 6.64.0) are affected. The vulnerability is specific to the staff role assignment functionality within these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalogue, suggesting that there is no known widespread exploitation at the time of this analysis. The exploit requires an authenticated account with Editor or Super Editor privileges; the attacker then abuses the lax role‑assignment check to elevate their own privileges or those of other staff users. Because the attack vector is internal and requires legitimate credentials, the risk is primarily confined to organizations that grant these roles without adequate oversight. Nonetheless, the ability to silently promote users to higher roles can be leveraged for broader attacks such as site takeover or persistent misuse of administrative privileges.
OpenCVE Enrichment