Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33953 | Connect-Multiparty allows arbitrary file upload |
Github GHSA |
GHSA-w2xw-44r3-4v9g | Connect-Multiparty allows arbitrary file upload |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 20 May 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file upload vulnerability in the file upload module of Connect-Multiparty v2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. | An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report. |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-20T06:09:26.360Z
Reserved: 2022-04-25T00:00:00.000Z
Link: CVE-2022-29623
No data.
Status : Modified
Published: 2022-05-16T14:15:08.067
Modified: 2025-05-20T06:15:38.267
Link: CVE-2022-29623
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA