Executive brief
Ghost is a popular open-source platform for building websites and publishing content. A vulnerability in an unused endpoint allows attackers to trick logged-in Ghost administrators into clicking a malicious link, which grants the attacker full access to the Ghost Admin interface without requiring any credentials. This could lead to unauthorized changes to website content, theft of sensitive data, or complete takeover of the website.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in the /ghost/preview endpoint, an unused feature added during Ghost 4.0.0 development. The vulnerability allows reflected XSS attacks via malicious query parameters. An attacker can craft a link containing JavaScript payload and trick an authenticated Ghost admin user into clicking it; when clicked, the payload executes in the victim's browser with their admin privileges, enabling account takeover and unauthorized administrative actions. The fix, released in Ghost 4.3.3, simply removes the unused endpoint entirely. Versions 4.0.0 through 4.3.2 are affected; workarounds include blocking the /ghost/preview path at the web server level.
Affected products
- Ghost Ghost 4.0.0 to 4.3.2
Timeline
- 2021-04-29: disclosed
- 2021-04-29: patched: Fixed in Ghost 4.3.3