Intel

CVE-2022-29622

formidable is vulnerable to RCE

RCE Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 16, 2022

98

Critical Risk

This Affects:

formidable
Are you affected? Scan for Free

TL;DR

An arbitrary file upload vulnerability in formidable allows attackers to execute arbitrary code via a crafted filename

Who does this affect?

You're running formidable before v3.2.4.

Background info

formidable is vulnerable to RCE.

How to fix this

Aikido recommends upgrading to formidable 3.5.0, because versions before that are incompatible with some JS builds. When used by 'superagent', Aikido recommends upgrading the superagent package to v9.0.0+ to maintain compatibility.