Description
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
Remediation
References
https://github.com/kindsoft/kindeditor/issues/337
Related Vulnerabilities
CVE-2020-8137 Vulnerability in maven package org.webjars.npm:uppy
CVE-2020-26256 Vulnerability in npm package @fast-csv/parse
CVE-2021-29486 Vulnerability in npm package cumulative-distribution-function
CVE-2023-28155 Vulnerability in maven package org.webjars:request
CVE-2020-26302 Vulnerability in maven package org.webjars.npm:is_js