漏洞描述
Ghost CMS 4.0.0 to 4.3.2 contains a DOM cross-site scripting vulnerability. An unused endpoint added during the development of 4.0.0 allows attackers to gain access by getting logged-in users to click a link containing malicious code.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/TryGhost/Ghost/security/advisories/GHSA-9fgx-q25h-jxrg↗www.npmjs.comhttps://www.npmjs.com/package/ghost↗forum.ghost.orghttps://forum.ghost.org/t/critical-security-update-available-for-ghost-4-x/22290↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-29484↗github.comhttps://github.com/ARPSyndicate/cvemon↗github.comhttps://github.com/TryGhost/Ghost/blob/95651b33a66f3240535a61999b292a725f1b3317/core/server/web/admin/views/preview.html↗www.sonarsource.comhttps://www.sonarsource.com/blog/ghost-admin-takeover/↗