Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
相对路径遍历
Vulnerability Title
CKSource CKFinder 安全漏洞
Vulnerability Description
CKSource CKFinder是美国CKSource公司的一个文件管理和上传工具。 CKSource CKFinder 2.5.0.1之前版本存在安全漏洞,该漏洞源于认证用户可通过正确路径下载服务器上的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A