CKSource CKFinder
cpe:2.3:a:cksource:ckfinder:*:*:*:*:asp.net:*:*
- < 2.5.0.1
A vulnerability in CKSource CKFinder for ASP.NET, prior to version 2.5.0.1, allows authenticated users to download any file from the server by providing the correct file path. This issue arises from insufficient restrictions on file access for authenticated users.
Exploitation of this vulnerability could lead to unauthorized file downloads from the server, potentially exposing sensitive information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.