Impact
Ghost, a Node.js content management system, had a flaw in its public donation checkout flow from versions 6.27.0 up to but not including 6.44.0. An unauthenticated user could manipulate the checkout metadata and receive a paid gift membership for a minimal payment. The attacker gains the privileges associated with the paid gift membership without exposing customer data or siphoning funds from the site. This flaw does not grant arbitrary code execution or data theft, but it undermines the business model and can erode customer trust in the platform's donation integrity.
Affected Systems
TryGhost Ghost CMS versions 6.27.0 through is resolved in version 6.44.0 and later.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium range. The EPSS score is less than 1%, indicating a very low probability of exploitation. It is not listed in CISA's KEV catalog. Based on the description, the likely attack vector no authentication or privileged context is required. An attacker can exploit the flaw simply by visiting the donation page and submitting manipulated metadata, thereby obtaining a paid gift membership at a marginal cost.
OpenCVE Enrichment