logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-47196

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-47196

Description:
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_head` for a post.
Last updated date:
06/23/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/25/2023
Reference url to background

https://talosintelligence.com/vulnerability_reports/TALOS-2022-1686

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy