VYPR

Vendor CVEs

Cesanta

All CVEs

151 total · sorted by risk
  • CVE-2022-25299CriFeb 18, 2022
    risk 0.00cvss 9.8epss 0.01

    This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

Page 4 of 4