ghost-blog

1 article
sort: new top best
clear filter
0 6/10

A reflected/stored XSS vulnerability in Ghost CMS's /ghost/api/v0.1/settings/ API endpoint affecting logo, cover_image, ghost_head, and ghost_foot parameters. While requiring authenticated admin/owner access, the vulnerability persists across multiple versions (1.24.9 through at least 2.2.0) and executes payloads on every page of the website.

Ghost VoidSec CORS Anywhere CVE (referenced but not specified)
itsecguy.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details