VDB
Sign up
HIGH7.5

GHSA-w4m6-x6c2-j5c9

Express-FileUpload Arbitrary File Overwrite

Details

An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server. This vulnerability is [debated by the package author](https://github.com/richardgirges/express-fileupload/issues/316).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-fileupload
Introduced in: 0

No fixed version published yet for express-fileupload (npm). Pin to a known-safe version or switch to an alternative.

References