CyberRota Analysis
AI-GeneratedThe vulnerability in Ghost versions from 2.10.0 to 6.63.0 allows unauthenticated attackers to exploit the content API, enabling them to enumerate staff members and leak sensitive user data through discrepancies in API metadata responses. Organizations using affected versions should prioritize remediation to prevent unauthorized data exposure and protect user privacy. This is particularly critical for those handling sensitive information or operating in regulated industries.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.