RSS   Vulnerabilities for 'Kindeditor'   RSS

2021-10-14
 
CVE-2021-42227

CWE-79
 

 
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).

 
 
CVE-2021-42228

CWE-352
 

 
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.

 
2021-09-28
 
CVE-2021-30086

CWE-79
 

 
Cross Site Scripting (XSS) vulnerability exists in KindEditor (Chinese versions) 4.1.12, which can be exploited by an attacker to obtain user cookie information.

 
 
CVE-2021-37267

CWE-79
 

 
Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information.

 
2019-02-06
 
CVE-2019-7543

CWE-79
 

 
In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.

 
2017-09-14
 
CVE-2017-1002024

CWE-287
 

 
Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.

 

 >>> Vendor: Kindsoft 2 Products
Kind editor
Kindeditor


Copyright 2024, cxsecurity.com

 

Back to Top