Ghost Foundation Ghost是Ghost开源的一款用 JavaScript 编写的个人博客系统。 Ghost Foundation Ghost 5.9.4存在安全漏洞,该漏洞源于Ghost Foundation Ghost 5.9.4 的创建后功能中存在一个不安全的默认漏洞。 Ghost 的默认安装允许非管理员用户在帖子中注入任意 Javascript,从而允许通过 XSS 将权限提升到管理员。 为了触发该漏洞,攻击者可以发送HTTP请求在帖子中注入Javascript,以诱使管理员访问帖
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ghost Foundation | Ghost | 5.9.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-47194 | Ghost Foundation Ghost 安全漏洞 | |
| CVE-2022-47195 | Ghost Foundation Ghost 跨站脚本漏洞 | |
| CVE-2022-47197 | Ghost Foundation Ghost 跨站脚本漏洞 |
No comments yet