CVE-2017-1002024

Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.
References
Link Resource
http://kindeditor.org Product
http://www.vapidlabs.com/advisory.php?v=195 Exploit Third Party Advisory
https://github.com/kindsoft/kindeditor Patch Third Party Advisory
http://kindeditor.org Product
http://www.vapidlabs.com/advisory.php?v=195 Exploit Third Party Advisory
https://github.com/kindsoft/kindeditor Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kindsoft:kind_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.8:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.9:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.10:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.11:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kindeditor:4.1.12:*:*:*:*:*:*:*

History

21 Nov 2024, 03:04

Type Values Removed Values Added
References () http://kindeditor.org - Product () http://kindeditor.org - Product
References () http://www.vapidlabs.com/advisory.php?v=195 - Exploit, Third Party Advisory () http://www.vapidlabs.com/advisory.php?v=195 - Exploit, Third Party Advisory
References () https://github.com/kindsoft/kindeditor - Patch, Third Party Advisory () https://github.com/kindsoft/kindeditor - Patch, Third Party Advisory

Information

Published : 2017-09-14 13:29

Updated : 2024-11-21 03:04


NVD link : CVE-2017-1002024

Mitre link : CVE-2017-1002024

CVE.ORG link : CVE-2017-1002024


JSON object : View

Products Affected

kindsoft

  • kind_editor
  • kindeditor
CWE
CWE-287

Improper Authentication