CVE-2026-104411

🟡 Monitoruj

Wykryta podatność XSS w Ghost umożliwia atakującym kompromitację sesji administratorów.

CVSS
7.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff users' admin sessions.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-10-02 12:17:10 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:17:00 UTC
Referencje