漏洞描述 CKSource FCKeditor(现称CKEditor)是波兰CKSource公司的一套开源的、基于网页的文字编辑器。该编辑器具有轻量化、易于安装等特点。 在Fckeditor 2.3.0 - 2.4.3版本中,在upload.php文件中,检测上传的类型时,已检查却未定义拒绝后缀,导致可以上传任意后缀文件。
相关漏洞推荐 O2OA 默认口令漏洞 ERG2 1350W 路由器默认口令漏洞 畅捷通-TPlus /tplus/ajaxpro/ASP_sm_setupaccount_versionupdate_selectbackupfileonserver_aspx App_Web_selectbackupfileonserver.aspx.1cbd2a00.ashx 目录遍历漏洞 WordPress Yoco Payments plugin /wp-json/yoco/logs 目录遍历漏洞(CVE-2025-13801) Frappe /api/method/frappe.automation.doctype.auto_repeat.auto_repeat.generate_message_preview SQL 注入漏洞(CVE-2025-68929) Frappe /files 目录遍历漏洞(CVE-2025-68953) POC CVE-2012-10018: WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload POC CVE-2024-24882: Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation POC CVE-2024-29138: WordPress Restrict User Access <= 2.5 - Cross-Site Scripting POC CVE-2025-52691: SmarterMail - Unrestricted File Upload POC CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure POC CVE-2006-3392: Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure POC CVE-2011-3600: Apache OFBiz - XML External Entity Injection