VDB
Sign up
HIGH8.8

GHSA-3ww4-cp53-6g2x

Cross Site Request Forgery in kindeditor

Details

Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x. First, you upload an html file containing csrf on the website that uses a google editor, (you only need to search in google: inurl:/examples/uploadbutton.html) and then use the authority of this website to trick users into clicking your malicious html link.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/kindeditor
Introduced in: 0

No fixed version published yet for kindeditor (npm). Pin to a known-safe version or switch to an alternative.

References