Description
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
Remediation
References
https://github.com/kindsoft/kindeditor/issues/337
Related Vulnerabilities
CVE-2018-16484 Vulnerability in npm package m-server
CVE-2022-25345 Vulnerability in npm package @discordjs/opus
CVE-2023-40813 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2022-27772 Vulnerability in maven package org.springframework.boot:spring-boot
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs