Insecure file upload In ghost
Description
Arbitrary file upload in Ghost An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 4.39.1 |
Aliases
1. 2. 3. 4.
References
1. 2.