Impact
Ghost adds a stored cross-site scripting flaw in versions 2.5.0 through 6.63. The vulnerability stems from unvalidated oEmbed photo responses that are persisted in post content. If an attacker supplies a crafted response that includes malicious JavaScript, the code executes whenever a Ghost editor, published page, or newsletter is viewed, potentially hijacking admin sessions and compromising site content.
Affected Systems
Affected systems are Ghost installations using any version from 2.5.0 up to but excluding 6.64.0. The key product is Ghost, a popular open-source CMS, and versions earlier than 6.64.0 are susceptible.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score is not available, so the probability of widespread exploitation cannot be precisely quantified. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker with the ability to upload or edit post content can host a malicious oEmbed photo response that, when resolved by Ghost, stores and later executes arbitrary JavaScript. Successful exploitation would allow the attacker to hijack admin sessions, alter published content, and embed malicious code into newsletter emails.
OpenCVE Enrichment