OSV 1.4.0 · github-reviewed · 修改于 2021-10-21 22:56
发布时间
2021-10-19 03:44
GitHub 审查时间
2021-10-16 01:38
NVD 发布时间
2021-10-15 01:15
源文件
advisories/github-reviewed/2021/10/GHSA-3ww4-cp53-6g2x/GHSA-3ww4-cp53-6g2x.json
Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x. First, you upload an html file containing csrf on the website that uses a google editor, (you only need to search in google: inurl:/examples/uploadbutton.html) and then use the authority of this website to trick users into clicking your malicious html link.