Description
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The vendor does not view this as a valid vector."
Published: 2024-02-11
Score: 9.0 Critical
EPSS: 38.4% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-99vc-xw8j-phjm Ghost has possible Cross-site Scripting issue
History

Thu, 07 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-79
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*
Vendors & Products Ghost
Ghost ghost
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-07T19:30:18.958Z

Reserved: 2024-01-21T00:00:00.000Z

Link: CVE-2024-23724

cve-icon Vulnrichment

Updated: 2024-08-01T23:13:07.225Z

cve-icon NVD

Status : Modified

Published: 2024-02-11T01:15:08.080

Modified: 2024-11-21T08:58:14.880

Link: CVE-2024-23724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses