Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g78m-xpj3-3hwr

Опубликовано: 19 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the facebook field for a user.

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the facebook field for a user.

EPSS

Процентиль: 58%
0.00368
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-453
CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `facebook` field for a user.

CVSS3: 5.4
debian
около 3 лет назад

An insecure default vulnerability exists in the Post Creation function ...

EPSS

Процентиль: 58%
0.00368
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-453
CWE-79