CyberRota Analysis
AI-GeneratedThe vulnerability in Ghost versions prior to 6.64.0 allows staff users with invite viewing permissions to access secret tokens for pending staff invites, potentially enabling them to accept invites for higher-privileged roles and escalate their privileges. Organizations using affected versions of Ghost should prioritize patching to mitigate the risk of unauthorized privilege escalation and protect sensitive administrative functions. This issue is particularly critical for environments where multiple staff users have varying levels of access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.