Описание
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.11 (включая)
cpe:2.3:a:kindeditor:kindeditor:*:*:*:*:*:*:*:*
EPSS
Процентиль: 69%
0.00592
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
EPSS
Процентиль: 69%
0.00592
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22