CVE-2024-23724 affects Ghost through version 5.76.0. The issue is a stored cross-site scripting vulnerability in profile picture handling: a contributor can upload an SVG profile image containing embedded JavaScript. When the malicious SVG is rendered, the script executes in the application context and can interact with the Ghost API exposed on localhost TCP port 3001. According to the provided description, this enables a low-privileged contributor to escalate privileges and take over arbitrary accounts. The available information does not identify a specific vulnerable function beyond SVG profile picture processing/rendering.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Python-based exploit for Ghost CMS targeting CVE-2024-23724. The main script, 'ghost-cms.py', first attempts to brute-force valid admin credentials using supplied username and password wordlists. Upon successful authentication, it checks for the presence of the vulnerability and, if found, generates a malicious SVG payload ('tenant-takeover.svg') using a template ('boilerplate.svg'). The SVG payload contains embedded JavaScript that, when rendered, sends crafted API requests to Ghost CMS admin endpoints to escalate privileges or take over user accounts. The exploit assumes the target Ghost CMS instance is running on port 3001 and requires the attacker to supply wordlists and the SVG template. The repository consists of three files: a README with usage instructions, the Python exploit script, and the SVG template containing the JavaScript payload logic. The exploit is operational, providing a working attack chain from brute-force to privilege escalation via a crafted SVG file.
This repository provides a proof-of-concept exploit for CVE-2024-23724, a privilege escalation vulnerability in Ghost CMS. The exploit leverages the ability for a contributor-level user to upload a malicious SVG file as their profile image. The SVG contains embedded JavaScript that, when rendered in the admin interface (e.g., when an administrator views the contributor's profile image), executes API requests to escalate the contributor's privileges to Administrator and then to Owner. The repository includes: - Python script (`generate-malicious-svg.py`) to automate the creation of a malicious SVG file tailored to the target instance and user. - SVG templates (`boilerplate.svg`, `simple-malicious.svg`) with embedded JavaScript payloads. - Docker Compose and setup scripts to facilitate local testing of Ghost CMS with the required user roles and database state. - Documentation (`readme.md`) with detailed setup and exploitation instructions, including credentials for test accounts and a video demonstration. The main attack vector is browser-based: the exploit is triggered when an administrator views the malicious SVG profile image, causing the browser to execute the embedded JavaScript in the context of the admin session. The exploit targets the Ghost CMS admin API endpoints on `http://localhost:3001`. Overall, the repository is well-structured for demonstrating and testing the vulnerability, providing both automated and manual setup options, and clear instructions for exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.