CRITICAL 9.8 npm
Arbitrary file upload in Ghost
GHSA-fvc6-qjp7-m4g4 · BIT-ghost-2022-27139 · CVE-2022-27139
Published · Modified
Description
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file.
Ready to move
Start Securing
Free, no credit card | First findings in minutes