Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.
- https://hackerone.com/reports/793704
- https://hackerone.com/reports/815084
No PoCs found on GitHub currently.