← back
CVE-2023-40028mediumCWE-22

Arbitrary file read via symlinks in Ghost

45Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 4.9epss 58%
from disclosure to weapon221 days
Published on NVDAug 15
1st PoC+221d
exploitation probability
58%top 1% of all CVEs
observed exploitation
nono source reports it
11 public exploit(s)
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
TryGhost · Ghost
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.