安全研究

CVE-2024-23724 Ghost CMS SVG 存储型 XSS:从头像上传到 Owner 权限接管

#漏洞分析#代码审计#Web安全
深色档案背景下的 Ghost 头像与 Owner 角色接管路径

Ghost CMS 允许用户上传 SVG 作为头像但没有 sanitize,攻击者用含 JS 的 SVG 偷 Owner 的会话,触发 XSS 后能把自己提权为 Admin 再升 Owner。

Unlock to view this content.