Path Traversal Vulnerability in KindEditor through 4.1.11: Unauthenticated File and Directory Browsing
CVE-2018-18950 · MEDIUM Severity
AV:N/AC:L/AU:N/C:P/I:N/A:N
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
Learn more about our Web Application Penetration Testing UK.