CyberRota Analysis
AI-GeneratedGhost versions prior to 6.62.0 are vulnerable to an authentication bypass that enables suspended staff users to reactivate their accounts via self-service password reset. This flaw allows attackers with suspended credentials to regain access and restore their privileges, posing a significant security risk. Organizations using affected versions should prioritize immediate updates to mitigate potential account takeovers.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.