S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-29484 Scanner

CVE-2021-29484 scanner - Cross-Site Scripting (XSS) vulnerability in Ghost

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-29484
6.8
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've visited a malicious site. Ghost(Pro) has already been patched. We can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a version between 4.0.0 and 4.3.2. Immediate action should be taken to secure your site. The issue has been fixed in 4.3.3, all 4.x sites should upgrade as soon as possible. As the endpoint is unused, the patch simply removes it. As a workaround blocking access to /ghost/preview can also mitigate the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Ghostby TryGhost
>= 4.0.0, < 4.3.3
Updated Aug 21, 2026View on NVD →
Detail

Ghost is a Node.js-based CMS (Content Management System) that is used for publishing and managing online content. It is used by individuals, businesses, bloggers, and publishers to create and manage digital content with ease. Ghost is hailed as one of the best CMS platforms around due to its open-source framework, simplicity, and great speed. Its free version is robust and packed with powerful features, while Ghost(Pro) is the paid version that comes with additional features such as automatic security updates, backups, and more.

The CVE-2021-29484 vulnerability, which was found during the development of Ghost 4.0.0, has left sites using versions between 4.0.0 and 4.3.2 vulnerable to exploit by untrusted users. Attackers can gain access to the Ghost Admin by getting logged in users to click on a link that contains malicious code. This can happen without the user entering any credentials, making the situation even more dangerous. Ghost (Pro) already provided a fix for this vulnerability, but self-hosters using Ghost versions between 4.0.0 and 4.3.2 need to secure their sites as soon as possible.

If this vulnerability is exploited, it can lead to serious consequences, such as unauthorized access to sensitive information, modifications to website content, and even data theft. This can be disastrous for businesses, publishers, and individuals who rely on Ghost CMS to manage their online content. The damage can be long-lasting, and it can take a lot of time and effort to recover from such an attack.

Thanks to the pro features of the s4e.io platform, users can easily stay up-to-date with the latest vulnerabilities in their digital assets. With real-time monitoring, proactive alerts, and detailed reports, the platform ensures that users have a complete understanding of their security posture at all times. Additionally, security experts are also on hand to provide support and guidance, helping users stay protected against vulnerabilities such as CVE-2021-29484.

 

REFERENCES

Solution Advice
To protect against this vulnerability, Ghost users should take the following precautions:- Upgrade to Ghost CMS version 4.3.3 immediately if they were running versions between 4.0.0 and 4.3.2.- Implement access control and password policies to limit unauthorized access to the Ghost Admin.- Educate users about this vulnerability and encourage them not to click on suspicious links or download unknown attachments.- Use a web application firewall to filter out malicious traffic and attempts to exploit vulnerabilities.- Implement regular data backups and disaster recovery plans to ensure that the site can be restored to a working state in case of a security breach.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-29484 scanner - Cross-Site Scripting (XSS) vulnerability in Ghost | S4E