Security Research

CVE-2024-23724 Ghost CMS SVG Stored XSS: from avatar upload to Owner takeover

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of Ghost avatar and Owner role takeover path

Ghost CMS lets users upload SVG files as avatars without sanitization. An attacker uses a JavaScript-bearing SVG to hijack the Owner’s session and escalate from Contributor to Admin to Owner.

Unlock to view this content.