QID 996818
Date Published: 2024-01-23
QID 996818: NodeJs (Npm) Security Update for ghost (GHSA-fh38-9fgr-454w)
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fh38-9fgr-454w for updates and patch information.
Vendor References
- GHSA-fh38-9fgr-454w -
github.com/advisories/GHSA-fh38-9fgr-454w
CVEs related to QID 996818
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fh38-9fgr-454w | ghost |
|