Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfr8-qfh4-r5rc

Опубликовано: 19 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the twitter field for a user.

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the twitter field for a user.

EPSS

Процентиль: 63%
0.00457
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-1188
CWE-453
CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `twitter` field for a user.

CVSS3: 5.4
debian
около 3 лет назад

An insecure default vulnerability exists in the Post Creation function ...

EPSS

Процентиль: 63%
0.00457
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-1188
CWE-453
CWE-79