Ghost Foundation Ghost是Ghost开源的一款用 JavaScript 编写的个人博客系统。 Ghost Foundation Ghost 5.9.4存在安全漏洞,该漏洞源于Ghost Foundation Ghost 5.9.4 的创建后功能中存在一个不安全的默认漏洞。 Ghost 的默认安装允许非管理员用户在帖子中注入任意 Javascript,从而允许通过 XSS 将权限提升到管理员。 要触发此漏洞,攻击者可以发送 HTTP 请求在帖子中注入 Javascript,以诱使管理员访
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ghost Foundation | Ghost | 5.9.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-47194 | Ghost Foundation Ghost 安全漏洞 | |
| CVE-2022-47196 | Ghost Foundation Ghost 安全漏洞 | |
| CVE-2022-47197 | Ghost Foundation Ghost 跨站脚本漏洞 |
No comments yet