Ghost CMS 4.0.0 to 4.3.2 contains a DOM cross-site scripting vulnerability. An unused endpoint added during the development of 4.0.0 allows attackers to gain access by getting logged-in users to click a link containing malicious code.
View the template here CVE-2021-29484.yaml
References:
https://github.com/ARPSyndicate/cvemon