VYPR

npm package

kindeditor

pkg:npm/kindeditor

Vulnerabilities (2)

  • CVE-2021-42228Oct 14, 2021
    affected <= 4.1.12

    A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.

  • CVE-2021-42227Oct 14, 2021
    affected <= 4.1.12

    Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).