PT-2022-18246 · Unknown · Express-Fileupload
Shahbaz-Pucit
·
Published
2022-04-12
·
Updated
2024-08-03
·
CVE-2022-27140
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
express-fileupload version 1.3.1
Description
An arbitrary file upload vulnerability in the file upload module of express-fileupload allows attackers to execute arbitrary code via a crafted PHP file. The vendor's position is that the observed behavior can only occur with intentional misusing of the API, as the express-fileupload middleware is not responsible for an application's business logic, such as determining whether or how a file should be renamed.
Recommendations
For express-fileupload version 1.3.1, consider disabling the file upload module until a patch is available to prevent the execution of arbitrary code via crafted PHP files. Restrict access to the file upload functionality to minimize the risk of exploitation. Avoid using the file upload module with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Express-Fileupload