CyberRota Analysis
AI-GeneratedGhost, a Node.js content management system, is vulnerable in versions 6.10.3 to 6.64.0 due to improper handling of theme translation files, allowing authenticated Administrators to execute arbitrary code on the server through a malicious theme. The impact of this vulnerability is significant, as it could lead to unauthorized access and control over the server. Organizations using affected versions should prioritize upgrading to version 6.64.0 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.