ghost-cms

1 article
sort: new top best
clear filter
0 6/10

Authenticated XSS vulnerability in Ghost CMS API endpoint /ghost/api/v0.1/settings/ via PUT requests affecting logo, cover_image, ghost_head, and ghost_foot parameters. While requiring admin/owner privileges and limited by CORS/SOP in real-world scenarios, the vulnerability persists across multiple versions and was a rediscovery of a previously reported issue.

Ghost VoidSec SANS Holiday Hack Challenge KringleCon
itsecguy.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details