{"id":"CVE-2022-28397","details":"An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.","aliases":["BIT-ghost-2022-28397","GHSA-ffhq-g856-9f2p"],"modified":"2026-08-12T03:51:14.100603125Z","published":"2022-04-12T16:29:06Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28397.json","cna_assigner":"mitre","isDisputed":true},"references":[{"type":"WEB","url":"https://ghost.org/customers/"},{"type":"WEB","url":"https://ghost.org/docs/security/#privilege-escalation-attacks"},{"type":"WEB","url":"https://trends.builtwith.com/cms/Ghost"},{"type":"WEB","url":"https://youtu.be/PncfBetPk2g"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28397.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28397"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tryghost/ghost","events":[{"introduced":"2fdf8fd4b6c3f6d094d48df137dcb7a40f797b61"},{"last_affected":"2fdf8fd4b6c3f6d094d48df137dcb7a40f797b61"}],"database_specific":{"cpe":"cpe:2.3:a:ghost:ghost:4.42.0:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"4.42.0"},{"last_affected":"4.42.0"}],"source":"CPE_STRING"}}],"versions":["4.42.0","v4.42.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28397.json"}}],"schema_version":"1.9.0"}