#VU71368 Insecure Default Variable Initialization in Ghost - CVE-2022-47196
Published: January 20, 2023
Ghost
Ghost Foundation
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an insecure default variable initialization in the codeinjection_head. A remote user can inject arbitrary Javascript in posts, leading to privilege escalation to administrator via stored XSS vulnerability in the twitter field.