CVE-2022-27261: Malicious File Upload
An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27261?
CVE-2022-27261 is an arbitrary file write vulnerability in Express-FileUpload v1.3.1.
How does the vulnerability in Express-FileUpload v1.3.1 allow attackers to compromise the server?
The vulnerability allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.
What is the severity of CVE-2022-27261?
The severity of CVE-2022-27261 is high with a CVSS score of 7.5.
How can I fix the arbitrary file write vulnerability in Express-FileUpload v1.3.1?
To fix the vulnerability, upgrade to a version of Express-FileUpload that is not affected, if available. Alternatively, consider using a different file upload library.
Where can I find more information about CVE-2022-27261?
You can find more information about CVE-2022-27261 in the references provided: https://nvd.nist.gov/vuln/detail/CVE-2022-27261