Описание
Connect-Multiparty allows arbitrary file upload
An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.
Пакеты
Наименование
connect-multiparty
npm
Затронутые версииВерсия исправления
<= 2.2.0
Отсутствует
Связанные уязвимости
CVSS3: 7.8
nvd
больше 3 лет назад
An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.