CVE-2024-23725: XSS
Published Jan 21, 2024
·Updated
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.
Affected Software
2 affected componentsFixes available
npm/ghost<5.76.0
5.76.0
Ghost Ghost Node.js<5.76.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/ghostto a version that resolves this vulnerability.Fixed in 5.76.0
Event History
Jan 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-23725?
CVE-2024-23725 is classified as a medium severity vulnerability due to its potential for XSS attacks via post excerpts.
2
How do I fix CVE-2024-23725?
To fix CVE-2024-23725, upgrade to Ghost version 5.76.0 or later.
3
What software is affected by CVE-2024-23725?
CVE-2024-23725 affects Ghost versions prior to 5.76.0.
4
What type of vulnerability is CVE-2024-23725?
CVE-2024-23725 is an XSS (Cross-Site Scripting) vulnerability that arises from improper handling of post excerpts.
5
Can CVE-2024-23725 be exploited by an unauthenticated user?
Yes, CVE-2024-23725 can potentially be exploited by unauthenticated users if they can manipulate post excerpts.