PT-2023-27222 · Ghost · Ghost
Ixsly
·
Published
2023-08-15
·
Updated
2025-12-21
·
CVE-2023-40028
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ghost versions prior to 5.59.1
Description
The issue allows authenticated users to upload files that are symlinks, which can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation by looking for unknown symlinks within Ghost's
content/ folder.Recommendations
For versions prior to 5.59.1, upgrade to version 5.59.1 to resolve the issue. As a temporary workaround, consider monitoring the
content/ folder for unknown symlinks and restricting file upload capabilities to trusted users until the upgrade can be applied.Exploit
Fix
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ghost