PT-2025-46989 · Ckfinder · Ckfinder
Published
2025-11-14
·
Updated
2025-11-14
·
CVE-2025-63830
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CKFinder version 1.4.3
Description
CKFinder 1.4.3 is susceptible to a Cross Site Scripting (XSS) issue within the File Upload function. An attacker can exploit this by uploading a specially crafted SVG file containing active content. The vulnerable component is the file upload functionality, which does not properly sanitize uploaded SVG files. The
File Upload function allows for the injection of malicious scripts through crafted SVG content.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ckfinder