#VU71369 Insecure Default Variable Initialization in Ghost - CVE-2022-47197
Published: January 20, 2023
Ghost
Ghost Foundation
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an insecure default variable initialization in the codeinjection_foot. A remote user can inject arbitrary Javascript in posts, leading to privilege escalation to administrator via stored XSS vulnerability in the twitter field.