CVE-2022-27140
Dashboard / Vulnerabilities / CVE-2022-27140
CVE-2022-27140
Summary:
Details: An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the express-fileupload middleware is not responsible for an application's business logic (e.g., determining whether or how a file should be renamed).
References: https://www.youtube.com/watch?v=4XpofFi84KI, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27140.json, https://nvd.nist.gov/vuln/detail/CVE-2022-27140, https://github.com/richardgirges/express-fileupload/issues/312#issuecomment-1134912967, https://github.com/richardgirges/express-fileupload/issues/329#issuecomment-1387288644
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
