Description
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
Remediation
References
https://github.com/kindsoft/kindeditor/issues/289
Related Vulnerabilities
CVE-2021-23700 Vulnerability in npm package merge-deep2
CVE-2020-2136 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2017-16173 Vulnerability in npm package utahcityfinder
CVE-2020-28477 Vulnerability in npm package immer
CVE-2020-7750 Vulnerability in npm package scratch-svg-renderer