Vulnerability record · CVE-2024-23724 · published 11 February 2024
CVE-2024-23724: Ghost cross-site scripting vulnerability
Ghost · Ghost
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The vendor does not view this as a valid vector."
Description
Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The vendor does not view this as a valid vector."
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2024-23724 | ExploitVendor Advisory |
| https://github.com/TryGhost/Ghost/pull/19646 | Patch |
| https://rhinosecuritylabs.com/blog/ | Third Party Advisory |
| https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2024-23724 | ExploitVendor Advisory |
| https://github.com/TryGhost/Ghost/pull/19646 | Patch |
| https://rhinosecuritylabs.com/blog/ | Third Party Advisory |
Track CVE-2024-23724 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23724), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.