#VU71367 Insecure Default Variable Initialization in Ghost - CVE-2022-47195
Published: January 20, 2023
Ghost
Ghost Foundation
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an insecure default variable initialization in the Post Creation functionality. A remote user can inject arbitrary Javascript in posts, leading to privilege escalation to administrator via stored XSS vulnerability in the twitter field.