CVE-2017-1002024

Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
larry_cashdollarCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
kindsoftkind_editor
𝑥
≤ 3.5.6
kindsoftkind_editor
4.0
kindsoftkind_editor
4.0.1
kindsoftkind_editor
4.0.2
kindsoftkind_editor
4.0.3
kindsoftkind_editor
4.0.4
kindsoftkind_editor
4.0.5
kindsoftkind_editor
4.0.6
kindsoftkind_editor
4.1
kindsoftkind_editor
4.1.1
kindsoftkind_editor
4.1.2
kindsoftkind_editor
4.1.3
kindsoftkind_editor
4.1.4
kindsoftkind_editor
4.1.5
kindsoftkind_editor
4.1.6
kindsoftkind_editor
4.1.7
kindsoftkind_editor
4.1.8
kindsoftkind_editor
4.1.9
kindsoftkind_editor
4.1.10
kindsoftkind_editor
4.1.11
kindsoftkindeditor
4.1.12
𝑥
= Vulnerable software versions