An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00334}

epss

{'score': 0.0032}


Tue, 20 May 2025 06:15:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in the file upload module of Connect-Multiparty v2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-20T06:09:26.360Z

Reserved: 2022-04-25T00:00:00.000Z

Link: CVE-2022-29623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-16T14:15:08.067

Modified: 2025-05-20T06:15:38.267

Link: CVE-2022-29623

cve-icon Redhat

No data.