.. / CVE-2021-29484

Exploit for Ghost CMS <=4.32 - Cross-Site Scripting (CVE-2021-29484)

Description:

Ghost CMS 4.0.0 to 4.3.2 contains a DOM cross-site scripting vulnerability. An unused endpoint added during the development of 4.0.0 allows attackers to gain access by getting logged-in users to click a link containing malicious code.

Nuclei Template

View the template here CVE-2021-29484.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-29484.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-29484
https://www.npmjs.com/package/ghost
https://forum.ghost.org/t/critical-security-update-available-for-ghost-4-x/22290
https://github.com/TryGhost/Ghost/security/advisories/GHSA-9fgx-q25h-jxrg