Path Traversal Vulnerability in KindEditor through 4.1.11: Unauthenticated File and Directory Browsing

Path Traversal Vulnerability in KindEditor through 4.1.11: Unauthenticated File and Directory Browsing

CVE-2018-18950 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.

Learn more about our Web Application Penetration Testing UK.