An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.
History

Tue, 20 May 2025 06:15:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in the file upload module of Connect-Multiparty v2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-16T13:28:41.000Z

Updated: 2025-05-20T06:09:26.360Z

Reserved: 2022-04-25T00:00:00.000Z

Link: CVE-2022-29623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-16T14:15:08.067

Modified: 2025-05-20T06:15:38.267

Link: CVE-2022-29623

cve-icon Redhat

No data.