An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-ffhq-g856-9f2p Arbitrary file upload in Ghost
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T05:56:15.251Z

Reserved: 2022-04-04T00:00:00

Link: CVE-2022-28397

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-12T17:15:10.730

Modified: 2024-11-21T06:57:17.540

Link: CVE-2022-28397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses