QID 980375
QID 980375: Nodejs (npm) Security Update for kindeditor (GHSA-3ww4-cp53-6g2x)
Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x. First, you upload an html file containing csrf on the website that uses a google editor, (you only need to search in google: inurl:/examples/uploadbutton.html) and then use the authority of this website to trick users into clicking your malicious html link.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3ww4-cp53-6g2x for updates pertaining to this vulnerability.
Vendor References
- GHSA-3ww4-cp53-6g2x -
github.com/advisories/GHSA-3ww4-cp53-6g2x
CVEs related to QID 980375
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3ww4-cp53-6g2x | kindeditor |
|