CyberRota Analysis
AI-GeneratedVersions 5.2.0 through 6.61.0 of Ghost are vulnerable to exploitation by remote attackers who can manipulate the Stripe Checkout flow, allowing them to attach paid subscriptions to existing members, alter member names, and inject content into newsletters. This could lead to HTML injection or cross-site scripting (XSS) vulnerabilities, potentially compromising user data and security. Organizations using affected Ghost versions should prioritize patching to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendered, resulting in HTML injection or cross-site scripting (XSS).