express-fileupload

express-fileupload

Releases50
Frequency2 months 1 week
Last Release
Simple express file upload middleware that wraps around Busboy

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH4.3 MEDIUM

An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.