PT-2025-49222 · Cksource · Ckfinder For Asp.Net+1
Published
2025-12-05
·
Updated
2025-12-05
·
CVE-2016-20023
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CKSource CKFinder versions prior to 2.5.0.1 for ASP.NET
Description
Authenticated users could download any file from the server if the correct path to a file was provided. The issue occurs because of insufficient restrictions on file access.
Recommendations
Update CKSource CKFinder for ASP.NET to version 2.5.0.1 or later.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ckfinder
Ckfinder For Asp.Net