logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-47194

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-47194

Description:
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `twitter` field for a user.
Last updated date:
06/27/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/27/2023
Reference url to background

https://talosintelligence.com/vulnerability_reports/TALOS-2022-1686

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy