Description
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
Remediation
References
https://github.com/kindsoft/kindeditor/issues/337
Related Vulnerabilities
CVE-2020-2323 Vulnerability in maven package io.jenkins.plugins:chaos-monkey
CVE-2020-7708 Vulnerability in npm package irrelon-path
CVE-2021-21627 Vulnerability in maven package org.jenkins-ci.plugins:libvirt-slave
CVE-2021-44667 Vulnerability in maven package com.alibaba.nacos:nacos-common
CVE-2021-21368 Vulnerability in maven package org.webjars.npm:msgpack5