Insecure Default Vulnerability in Ghost Foundation's Ghost Product
CVE-2022-47194

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 January 2023

What is CVE-2022-47194?

A vulnerability exists in the Post Creation functionality of Ghost 5.9.4 that allows non-administrative users to inject arbitrary JavaScript into posts due to insecure default configurations. This may lead to privilege escalation via stored cross-site scripting (XSS). Specifically, an attacker could exploit the twitter field for a user to execute their injected scripts when an administrator is tricked into visiting the malicious post. Proper configurations and validation mechanisms are essential to mitigate this risk.

Affected Version(s)

Ghost 5.9.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

CVSS V3.0

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.