Back

CRITICAL

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file

Published Apr 12, 2022

Description

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 12, 2022
Updated Jul 9, 2026
Reserved Apr 4, 2022
NVD
Status Modified
Modified Jul 9, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-FFHQ-G856-9F2P