Executive brief
Ghost is a popular open-source content management system used to publish websites and newsletters. A vulnerability in its file upload module allows attackers to upload arbitrary files and execute malicious code on servers running Ghost, potentially compromising the entire system and any data it contains.
Technical details
An arbitrary file upload vulnerability (CWE-434) exists in Ghost CMS version 4.42.0 and earlier in the file upload handling module. The vulnerability allows unauthenticated network attackers to upload and execute arbitrary files without proper validation. Exploitation does not require authentication or user interaction, making it readily exploitable. Successful exploitation enables remote code execution, allowing attackers to compromise the server, access sensitive data, and pivot to other systems. Patches are available in newer Ghost versions.
Affected products
- Ghost Ghost 0 to 4.42.0
Timeline
- 2022-04-13: disclosed
- 2022-04-12: other: NVD published