Lucene search

K
osvGoogleOSV:GHSA-W4M6-X6C2-J5C9
HistoryApr 13, 2022 - 12:00 a.m.

Express-FileUpload Arbitrary File Overwrite

2022-04-1300:00:24
Google
osv.dev
6

0.001 Low

EPSS

Percentile

37.8%

An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server. This vulnerability is debated by the package author.

CPENameOperatorVersion
express-fileuploadle1.3.1

0.001 Low

EPSS

Percentile

37.8%

Related for OSV:GHSA-W4M6-X6C2-J5C9