CVE-2022-47196: XSS
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the codeinjectionhead for a post.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47196?
CVE-2022-47196 is considered a high severity vulnerability due to its potential for privilege escalation via arbitrary JavaScript injection.
How do I fix CVE-2022-47196?
To fix CVE-2022-47196, upgrade to a patched version of Ghost that addresses this insecure default configuration.
Who is affected by CVE-2022-47196?
Users of Ghost version 5.9.4 are affected by CVE-2022-47196 due to its insecure default installation.
What are the potential impacts of CVE-2022-47196?
CVE-2022-47196 can lead to unauthorized privilege escalation for non-administrator users who inject malicious scripts.
What action should I take if I'm using Ghost 5.9.4 and am concerned about CVE-2022-47196?
If you are using Ghost 5.9.4, you should immediately upgrade to a later secure version to mitigate the risks associated with CVE-2022-47196.