Page 2 of 9 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page. Una vulnerabilidad de Cross Site Scrtpting (XSS) en KodExplorer 4.45 permite a los atacantes remotos ejecutar código arbitrario a través de la página /index.php. • https://github.com/kalcaddle/KodExplorer/issues/482 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field. • https://github.com/Trinity-SYT-SECURITY/XSS_vuln_issue/blob/main/KodExplorer4.51.03.md https://github.com/kalcaddle/KodExplorer https://www.chtsecurity.com/news/13a86b33-7e49-4167-9682-7ff3f51cbcba%20 https://www.chtsecurity.com/news/55f0a781-f7bf-4b2f-b2cc-7957fdf846da • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 3

A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://www.exploit-db.com/exploits/51388 https://github.com/MrEmpy/CVE-2022-4944 https://github.com/kalcaddle/KodExplorer/issues/512 https://github.com/kalcaddle/KodExplorer/releases/tag/4.50 https://vuldb.com/?ctiid.227000 https://vuldb.com/?id.227000 https://www.mediafire.com/file/709i2vxybergtg7/poc.zip/file • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been addressed in version 4.50. Users are advised to upgrade. • https://github.com/kalcaddle/KodExplorer/commit/1f7072c0e12150686f10ee8cda82c004f04be98c https://github.com/kalcaddle/KodExplorer/security/advisories/GHSA-6f8p-4w5q-j5j2 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •