PT-2026-27133 · Unknown · Kalcaddle Kodbox

Vuldb

+1

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-4589

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kalcaddle kodbox version 1.64
Description A server-side request forgery condition exists in the PathDriverUrl function within the file /workspace/source-code/app/controller/explorer/editor.class.php of the fileGet Endpoint component. Manipulation of the path argument can lead to exploitation. The issue is remotely exploitable. The exploit is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-4589

Affected Products

Kalcaddle Kodbox