CVE-2017-1002024

Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.
References
Link Resource
https://github.com/kindsoft/kindeditor Patch Third Party Advisory
http://www.vapidlabs.com/advisory.php?v=195 Exploit Third Party Advisory
http://kindeditor.org Product
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kindsoft:kind_editor:4.1.11:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.9:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kindeditor:4.1.12:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.10:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.8:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.1:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:4.0:*:*:*:*:*:*:*
cpe:2.3:a:kindsoft:kind_editor:*:*:*:*:*:*:*:*

Information

Published : 2017-09-14 06:29

Updated : 2019-10-02 17:03


NVD link : CVE-2017-1002024

Mitre link : CVE-2017-1002024


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

kindsoft

  • kindeditor
  • kind_editor