Description
The Ghost CMS is vulnerable to a path traversal vulnerability. An unauthenticated attacker can read arbitrary files within the active theme's folder.
Remediation
Upgrade to the latest version of Ghost CMS
References
Related Vulnerabilities
OpenSSL Uncontrolled Resource Consumption Vulnerability (CVE-2016-8610)
Next.js CVE-2023-46298 Vulnerability (CVE-2023-46298)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0165)
Apache Tomcat Resource Management Errors Vulnerability (CVE-2011-4858)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-21336)