9.8

CVE-2022-28397

Exploit
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GhostGhost Version4.42.0 SwPlatformnode.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.48% 0.876
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

http://ghost.com
Product
https://ghost.org/customers/
Product
https://ghost.org/docs/security/#privilege-escalation-attacks
https://github.com/TryGhost/Ghost
Third Party Advisory
https://trends.builtwith.com/cms/Ghost
Product
https://youtu.be/PncfBetPk2g
Third Party Advisory
Exploit