Beveiligingsadvies

CVE-2022-28397

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-04-12 16:29:06
Laatst bijgewerkt 2026-07-09 00:18:33
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.