Title:Ghost Foundation Ghost 跨站脚本漏洞 (CVE-2022-47197) Description:Ghost Foundation Ghost是Ghost开源的一款用 JavaScript 编写的个人博客系统。 Ghost Foundation Ghost 5.9.4版本存在跨站脚本漏洞。攻击者利用该漏洞发送HTTP请求,在帖子中注入Javascript,以诱骗管理员访问帖子。
1. It is advised to access via the original source first.2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.