PT-2024-25902 · Ghost · Ghost

·

CVE-2024-34448

·

Published

2024-05-22

·

Updated

2026-06-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghost versions prior to 5.82.0
Description The issue allows CSV Injection during a member CSV export.
Recommendations For Ghost versions prior to 5.82.0, update to version 5.82.0 or later to resolve the issue.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GHOST-2024-34448
CVE-2024-34448
GHSA-XGWH-CGV9-783V

Affected Products

Ghost