CVE-2022-28397 is an arbitrary file upload vulnerability in Ghost CMS v4.42.0, allowing attackers to execute arbitrary code through crafted file uploads. This critical vulnerability (CVSS 9.8) has a high impact on confidentiality, integrity, and availability, with a low attack complexity and no required privileges. While the vendor notes that only trusted users can upload files, limiting its broad exploitability, there is no evidence of active exploitation, and no public exploit code is available, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.42.0CPE matchmatch criteria | cpe:2.3:a:ghost:ghost:4.42.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.