CVE-2022-29623
ADVISORY - githubSummary
An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.
EPSS Score: 0.00448 (0.628)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Unrestricted Upload of File with Dangerous Type
ADVISORY - github
Unrestricted Upload of File with Dangerous Type
NIST
CREATED
UPDATED
ADVISORY IDCVE-2022-29623
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.8highGitHub
CREATED
UPDATED
ADVISORY IDGHSA-w2xw-44r3-4v9g
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.8highintheWild
CREATED
UPDATED
ADVISORY IDCVE-2022-29623
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-