CVE-2022-27261
Summary
| CVE | CVE-2022-27261 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-12 17:15:00 UTC |
| Updated | 2023-10-18 16:03:00 UTC |
| Description | An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995654 NodeJs (Npm) Security Update for express-fileupload (GHSA-w4m6-x6c2-j5c9)