Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-23724 PoC — Ghost 跨站脚本漏洞

Source
Associated Vulnerability
Title: Ghost 跨站脚本漏洞 (CVE-2024-23724)
Description:Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The vendor does not view this as a valid vector."
Description
Ghost-CMS Exploit is python script. This script first performs brute-force authentication attempts using the provided wordlists. If valid credentials are found, it proceeds to check for CVE-2024-23724 vulnerability and generates an exploit payload if vulnerable.
Readme
# Ghost-CMS-Exploit
Ghost-CMS Exploit is python script. This script first performs brute-force authentication attempts using the provided wordlists. If valid credentials are found, it proceeds to check for CVE-2024-23724 vulnerability and generates an exploit payload if vulnerable.

**Requirements:**
1. Python 3.x installed
2. Install required library: `pip install requests`
3. A `boilerplate.svg` file in the same directory (used for generating the exploit payload)
4. Wordlist files for usernames and passwords

**Usage:**
```bash
python3 ghost-cms.py -U userlist.txt -P passlist.txt -t http://target-domain
```

**Features:**
1. Brute-force attack with progress reporting
2. Session management for successful logins
3. Automatic CVE-2024-23724 vulnerability check
4. SVG payload generation for confirmed vulnerabilities
5. Timeout handling for network requests
6. Error handling for file operations and network issues

**Note:**
- The target URL should be provided without the port (e.g., http://localhost)
- The script assumes Ghost CMS is running on port 3001
- Wordlist files should contain one credential per line
- The boilerplate.svg file should contain the appropriate placeholders used in the original script
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →