📦

ckfinder

Vendor: cksource

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 0.80% Exploit Prob.
Latest CVE CVE-2016-20023 Dec 05

Security Vulnerability Index

Page 1 / 1
5.0 CVSS

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

EPSS: 0.34%
6.1 CVSS

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

EPSS: 0.25%
5.3 CVSS

An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.

EPSS: 1.09%
7.5 CVSS

An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.

EPSS: 1.52%