Description
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
Remediation
References
https://github.com/kindsoft/kindeditor/issues/337
Related Vulnerabilities
CVE-2021-23383 Vulnerability in maven package org.webjars.npm:handlebars
CVE-2021-23342 Vulnerability in npm package docsify
CVE-2020-7765 Vulnerability in npm package @firebase/util
CVE-2021-43862 Vulnerability in npm package jquery.terminal
CVE-2022-24279 Vulnerability in npm package madlib-object-utils