Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vx4r-h2xh-2c27

Опубликовано: 19 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the codeinjection_head for a post.

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the codeinjection_head for a post.

EPSS

Процентиль: 38%
0.00164
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-1188
CWE-453
CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_head` for a post.

CVSS3: 5.4
debian
около 3 лет назад

An insecure default vulnerability exists in the Post Creation function ...

EPSS

Процентиль: 38%
0.00164
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-1188
CWE-453
CWE-79