Beveiligingsadvies

CVE-2022-25299

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-02-18 12:55:21
Laatst bijgewerkt 2024-09-16 17:52:54
Toegewezen door snyk
CVSS-score 9.8
Status PUBLISHED

Beschrijving

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.