PT-2022-19000 · Ghost Cms · Ghost Cms

CVE-2022-28397

·

Published

2022-04-12

·

Updated

2026-07-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghost CMS version 4.42.0
Description An arbitrary file upload vulnerability in the file upload module of Ghost CMS allows attackers to execute arbitrary code via a crafted file. The vendor states that files can only be uploaded and published by trusted users, which is intentional.
Recommendations For Ghost CMS version 4.42.0, consider restricting file upload capabilities to trusted users as a mitigation measure until a patch is available. As a temporary workaround, consider disabling the file upload module to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GHOST-2022-28397
CVE-2022-28397
GHSA-FFHQ-G856-9F2P

Affected Products

Ghost Cms