Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.1"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.4"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.5"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.6"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.9"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.10"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.11"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.12"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.5.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.1.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.1.8"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1002024.json"