PT-2022-19000 · Ghost Cms · Ghost Cms
Published
2022-04-12
·
Updated
2024-08-03
·
CVE-2022-28397
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ghost CMS version 4.42.0
Description
An arbitrary file upload vulnerability in the file upload module of Ghost CMS allows attackers to execute arbitrary code via a crafted file. The vendor states that files can only be uploaded and published by trusted users, which is intentional.
Recommendations
For Ghost CMS version 4.42.0, consider restricting file upload capabilities to trusted users as a mitigation measure until a patch is available. As a temporary workaround, consider disabling the file upload module to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghost Cms