Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vw7m-649j-qh5x

Опубликовано: 19 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the codeinjection_foot for a post.

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the codeinjection_foot for a post.

EPSS

Процентиль: 80%
0.01321
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-453
CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_foot` for a post.

CVSS3: 5.4
debian
около 3 лет назад

An insecure default vulnerability exists in the Post Creation function ...

EPSS

Процентиль: 80%
0.01321
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-453
CWE-79