CVE-2022-4944 EXPLOIT
4.3
MEDIUM · CVSS 3.1 · EPSS 2.7% (pctl 85)
Patch early
A public exploit exists.
Description
A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.50 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227000.
Scoring
| CVSS | 4.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
| EPSS | 2.67% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-04-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| kodcloud | kodexplorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | KodExplorer 4.49 - CSRF to Arbitrary File Upload | 2023-04-25 |
References
- https://github.com/kalcaddle/KodExplorer/issues/512
- https://github.com/kalcaddle/KodExplorer/releases/tag/4.50
- https://vuldb.com/?ctiid.227000
- https://vuldb.com/?id.227000
- https://www.mediafire.com/file/709i2vxybergtg7/poc.zip/file
- https://github.com/kalcaddle/KodExplorer/issues/512
- https://github.com/kalcaddle/KodExplorer/releases/tag/4.50
- https://vuldb.com/?ctiid.227000
- https://vuldb.com/?id.227000
- https://www.mediafire.com/file/709i2vxybergtg7/poc.zip/file
→ the Explorer · watch your stack · NVD