CVE-2020-7699

HIGH

Express-fileupload < 1.1.8 - Prototype Pollution

Title source: rule

Description

This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.

Exploits (1)

nomisec WORKING POC
by zodiac12-pub · poc
https://github.com/zodiac12-pub/CVE-2020-7699_reproduce

Scores

CVSS v3 7.5
EPSS 0.0409
EPSS Percentile 88.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1321
Status published
Products (3)
express-fileupload_project/express-fileupload < 1.1.8
netapp/max_data
npm/express-fileupload 0 - 1.1.9npm
Published Jul 30, 2020
Tracked Since Feb 18, 2026