cve/2018/CVE-2018-18950.md
2024-05-26 14:27:05 +02:00

831 B

CVE-2018-18950

Description

KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.

POC

Reference

No PoCs from references.

Github