Insecure Default in Ghost Foundation Ghost 5.9.4 Allows JavaScript Injection
CVE-2022-47195

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 January 2023

What is CVE-2022-47195?

A security vulnerability exists in the Post Creation functionality of Ghost Foundation's Ghost version 5.9.4. This flaw allows non-administrator users to inject arbitrary JavaScript into posts due to insecure default settings. An attacker can exploit this by sending a crafted HTTP request to include malicious JavaScript in a post, potentially tricking an administrator into visiting the compromised post. A stored XSS vulnerability is also present in the facebook field for user profiles, further increasing the risk of privilege escalation to administrator level.

Affected Version(s)

Ghost 5.9.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

CVSS V3.0

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.