Description
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.1.12
References
Could your website be exposed too?
SmartScanner can check your website for Cross site scripting in kindeditor and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site Scripting in epubjs - CVE-2021-33040
- Cross-site Scripting in bootstrap-table - bootstrap-table - CVE-2021-23472
- Cross-site Scripting in sanitize-url - CVE-2021-23648
- Cross site scripting in datatables.net - CVE-2021-23445
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


