Critical severity9.8NVD Advisory· Published May 16, 2022· Updated Jun 17, 2026
CVE-2022-29354
CVE-2022-29354
Description
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.
Affected products
3- cpe:2.3:a:keystonejs:keystone:4.2.1:*:*:*:*:node.js:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: =4.2.1
Patches
Vulnerability mechanics
References
1- www.youtube.com/watchnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.