Ghost CMS 4.0.0 to 4.3.2 contains a DOM cross-site scripting vulnerability. An unused endpoint added during the development of 4.0.0 allows attackers to gain access by getting logged-in users to click a link containing malicious code.
id: CVE-2021-29484
info:
name: Ghost CMS <=4.32 - Cross-Site Scripting
author: rootxharsh,iamno
...