|
| Description: | | Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The vendor does not view this as a valid vector." |
|
| Impact: | | An authenticated contributor of Ghost CMS through 5.76.0 uploads a malicious SVG profile picture with embedded JavaScript. When the Owner views the profile, the JS executes in their browser and performs a two-step API attack (privilege escalation + ownership transfer) via localhost:3001, achieving full tenant takeover. |
|
| Affected OS: | | Windows, Linux, Others |
|
| Reference: | | https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2024-23724 https://github.com/TryGhost/Ghost/pull/19646 https://rhinosecuritylabs.com/blog/
|
|