CNNVD-202511-1683 Information

CNNVD ID

CNNVD-202511-1683

CVE-2025-63830

  • CNNVD Published: 2025-11-14

Description (Chinese)

CKFinder是一款具有协作编辑功能的智能WYSIWYG编辑器组件。 CKFinder 1.4.3版本存在安全漏洞,该漏洞源于文件上传功能存在跨站脚本漏洞,可能导致上传恶意SVG文件。

Description (English)

CKFinder is a smart WYSIWYG editor component with collaborative editing functions. There is a security loophole in version 1.4.3 of CKFinder, which stems from the cross-site script gap in the document upload function, which may lead to the uploading of malicious SVG documents.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

个人开发者

Published

2025-11-14

Last Modified

2026-02-24

References

https://ckeditor.com/ckfinder/changelog/ https://github.com/Shubham03007/CVE-2025-63830/blob/main/README.md https://access.redhat.com/security/cve/cve-2025-63830

Patch

https://ckeditor.com/ckfinder/changelog/

Share on: