CVE-2020-7699 is a critical vulnerability affecting the express-fileupload package (versions prior to 1.1.8) and related products, including NetApp's express-fileupload and max_data. If the 'parseNested' option is enabled, an unauthenticated attacker can send a crafted HTTP request to achieve denial of service or arbitrary code execution. This vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild, nor are there public exploit modules like Metasploit or Nuclei, it has garnered some community discussion and media attention, including a BleepingComputer article highlighting its potential for code injection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.8CPE matchmatch criteria | cpe:2.3:a:express-fileupload_project:express-fileupload:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:max_data:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.