Cross Site Request Forgery in kindeditor
High severity
GitHub Reviewed
Published
Oct 18, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Oct 14, 2021
Reviewed
Oct 15, 2021
Published to the GitHub Advisory Database
Oct 18, 2021
Last updated
Feb 1, 2023
Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x. First, you upload an html file containing csrf on the website that uses a google editor, (you only need to search in google: inurl:/examples/uploadbutton.html) and then use the authority of this website to trick users into clicking your malicious html link.
References