Description
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
Remediation
References
https://github.com/kindsoft/kindeditor/issues/337
Related Vulnerabilities
CVE-2020-7722 Vulnerability in npm package nodee-utils
CVE-2020-15096 Vulnerability in npm package electron
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-kar
CVE-2021-29446 Vulnerability in npm package jose-node-cjs-runtime
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js