Ghost CMS Webmentions: SSRF Protections, Code Deep-Dive, and Origin IP leak
While I was pentesting my homelab for security reasons, I found that Ghost was leaking my IP address. How I Found It? I'm selfhosting this blog with I was testing Ghost sitting behind Caddy and Cloudflare. While I was testing Ghost routes I noticed something: every POST to