CVE-2022-46154
Arbitrary file access in KodExplorer
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been addressed in version 4.50. Users are advised to upgrade. There are no known workarounds for this issue.
Kodexplorer es un administrador de archivos basado en web en idioma chino y un editor de código basado en navegador. Las versiones anteriores a la 4.50 no impedían que los usuarios no autenticados solicitaran archivos arbitrarios del sistema de archivos del Sistema Operativo host. Como resultado, usuarios arbitrarios pueden acceder a cualquier archivo disponible para el proceso host. Este problema se solucionó en la versión 4.50. Se recomienda a los usuarios que actualicen. No se conocen soluciones para este problema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-28 CVE Reserved
- 2022-12-06 CVE Published
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/kalcaddle/KodExplorer/security/advisories/GHSA-6f8p-4w5q-j5j2 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/kalcaddle/KodExplorer/commit/1f7072c0e12150686f10ee8cda82c004f04be98c | 2022-12-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kodcloud Search vendor "Kodcloud" | Kodexplorer Search vendor "Kodcloud" for product "Kodexplorer" | < 4.50 Search vendor "Kodcloud" for product "Kodexplorer" and version " < 4.50" | - |
Affected
|