PT-2023-11769 · Unknown · Kindeditor

Wreck1Top

·

Published

2023-08-11

·

Updated

2023-08-17

·

CVE-2020-28717

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions kindeditor version 4.1.12
Description The issue is related to a Cross Site Scripting (XSS) vulnerability in the content1 parameter in demo.jsp of kindeditor. This allows attackers to execute arbitrary code.
Recommendations For kindeditor version 4.1.12, consider disabling the demo.jsp page or restricting access to it until a patch is available. Avoid using the content1 parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-28717

Affected Products

Kindeditor