Insecure Default Vulnerability in Ghost Foundation's Ghost Product
CVE-2022-47194
5.4MEDIUM
What is CVE-2022-47194?
A vulnerability exists in the Post Creation functionality of Ghost 5.9.4 that allows non-administrative users to inject arbitrary JavaScript into posts due to insecure default configurations. This may lead to privilege escalation via stored cross-site scripting (XSS). Specifically, an attacker could exploit the twitter field for a user to execute their injected scripts when an administrator is tricked into visiting the malicious post. Proper configurations and validation mechanisms are essential to mitigate this risk.
Affected Version(s)
Ghost 5.9.4
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
CVSS V3.0
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
