Unrated severityNVD Advisory· Published Dec 6, 2022· Updated Apr 23, 2025
Arbitrary file access in KodExplorer
CVE-2022-46154
Description
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been addressed in version 4.50. Users are advised to upgrade. There are no known workarounds for this issue.
Affected products
1- Range: < 4.50
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/kalcaddle/KodExplorer/commit/1f7072c0e12150686f10ee8cda82c004f04be98cmitrex_refsource_MISC
- github.com/kalcaddle/KodExplorer/security/advisories/GHSA-6f8p-4w5q-j5j2mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.