Description
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
Remediation
References
https://github.com/kindsoft/kindeditor/issues/337
Related Vulnerabilities
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2022-35278 Vulnerability in maven package org.apache.activemq:artemis-web
CVE-2022-39263 Vulnerability in npm package next-auth
CVE-2022-39135 Vulnerability in maven package org.apache.calcite:calcite-core