{"id":"BIT-ghost-2022-28397","details":"An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.","aliases":["CVE-2022-28397","GHSA-ffhq-g856-9f2p"],"modified":"2026-09-08T08:47:32.479536513Z","published":"2024-03-06T10:53:51.564Z","database_specific":{"cpes":["cpe:2.3:a:ghost:ghost:4.42.0:*:*:*:*:node.js:*:*","cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"],"severity":"Critical"},"references":[{"type":"WEB","url":"http://ghost.com"},{"type":"WEB","url":"https://ghost.org/customers/"},{"type":"WEB","url":"https://ghost.org/docs/security/#privilege-escalation-attacks"},{"type":"ADVISORY","url":"https://github.com/TryGhost/Ghost"},{"type":"WEB","url":"https://trends.builtwith.com/cms/Ghost"},{"type":"ADVISORY","url":"https://youtu.be/PncfBetPk2g"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28397"}],"affected":[{"package":{"name":"ghost","ecosystem":"Bitnami","purl":"pkg:bitnami/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.42.0"},{"fixed":"4.42.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2022-28397.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}