
Python exploit for CVE-2023-40028 enabling authenticated arbitrary file read on Ghost CMS, designed for educational use and HTB machines.
Exploit for CVE-2023-40028
for educational purposes
Built for HTB machine LinkVortex
python3 exploit.py <url> <user> <password>
Then enter the file path you want to read (e.g., /etc/passwd). Type exit to quit.