VYPR

Packagist (Composer) package

sunhater/kcfinder

pkg:composer/sunhater/kcfinder

Vulnerabilities (1)

  • CVE-2019-14315Jul 28, 2019
    affected <= 3.20-test2

    A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.