PT-2022-19000 · Ghost Cms · Ghost Cms

Published

2022-04-12

·

Updated

2024-08-03

·

CVE-2022-28397

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghost CMS version 4.42.0
Description An arbitrary file upload vulnerability in the file upload module of Ghost CMS allows attackers to execute arbitrary code via a crafted file. The vendor states that files can only be uploaded and published by trusted users, which is intentional.
Recommendations For Ghost CMS version 4.42.0, consider restricting file upload capabilities to trusted users as a mitigation measure until a patch is available. As a temporary workaround, consider disabling the file upload module to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BIT-GHOST-2022-28397
CVE-2022-28397
GHSA-FFHQ-G856-9F2P

Affected Products

Ghost Cms