An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.
{ "versions": [ { "introduced": "0" }, { "last_affected": "1.3.1" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-27261.json"