PT-2025-49222 · Cksource · Ckfinder For Asp.Net+1

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2016-20023

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CKSource CKFinder versions prior to 2.5.0.1 for ASP.NET
Description Authenticated users could download any file from the server if the correct path to a file was provided. The issue occurs because of insufficient restrictions on file access.
Recommendations Update CKSource CKFinder for ASP.NET to version 2.5.0.1 or later.

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2016-20023

Affected Products

Ckfinder
Ckfinder For Asp.Net