QID 980376
QID 980376: Nodejs (npm) Security Update for kindeditor (GHSA-wv83-jrfh-rp33)
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wv83-jrfh-rp33 for updates pertaining to this vulnerability.
Vendor References
- GHSA-wv83-jrfh-rp33 -
github.com/advisories/GHSA-wv83-jrfh-rp33
CVEs related to QID 980376
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wv83-jrfh-rp33 | kindeditor |
|