CyberRota Analysis
AI-GeneratedAuthenticated administrators using Ghost versions prior to 6.64.0 are vulnerable to a remote code execution flaw that allows the execution of arbitrary code through malicious theme translation files. This vulnerability poses a significant risk as it enables attackers with admin access to compromise the Ghost server by uploading crafted themes. Organizations utilizing affected versions should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.