peter bassill · operator
$ cve CVE-2022-4944 JSON

CVE-2022-4944 EXPLOIT

4.3
MEDIUM · CVSS 3.1 · EPSS 2.7% (pctl 85)

Patch early

A public exploit exists.

Description

A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.50 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227000.

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS2.67% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2023-04-22
Last modified2026-06-17

Affected (1)

VendorProduct
kodcloudkodexplorer

Public exploits

SourceTitleDate
exploit-dbKodExplorer 4.49 - CSRF to Arbitrary File Upload2023-04-25

References

→ the Explorer  ·  watch your stack  ·  NVD