Impact
Ghost CMS versions from 4.0.0 through 6.67.0 improperly store SVG images during content import without sanitization. When an attacker tricks an administrator into importing a crafted SVG file, the malicious code is embedded in the page content and subsequently executed in the context of any user who views that content, notably staff users with administrative privileges. This form of stored cross‑site scripting can allow the attacker to steal session tokens, bypass authentication, or perform further privileged actions on the site.
Affected Systems
The impact applies to installations of TryGhost Ghost CMS with content import functionality enabled, specifically versions 4.0.0 to 6.67.0 inclusive. Any deployment that permits SVG uploads in content imports during those release periods is affected.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and while EPSS data is unavailable, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires social engineering to persuade an administrator to import the malicious file; once imported, the payload the next time an administrator accesses the affected content can gain control of the admin session. Although not a remote code execution flaw, the potential to hijack privileged sessions raises the risk level above typical low‑impact XSS scenarios.
OpenCVE Enrichment