PT-2025-46989 · Ckfinder · Ckfinder

Published

2025-11-14

·

Updated

2025-11-14

·

CVE-2025-63830

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CKFinder version 1.4.3
Description CKFinder 1.4.3 is susceptible to a Cross Site Scripting (XSS) issue within the File Upload function. An attacker can exploit this by uploading a specially crafted SVG file containing active content. The vulnerable component is the file upload functionality, which does not properly sanitize uploaded SVG files. The File Upload function allows for the injection of malicious scripts through crafted SVG content.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63830

Affected Products

Ckfinder