References https://www.cnblogs.com/iAmSoScArEd/p/10575936.html https://blog.csdn.net/m0_65150886/article/details/135368686 https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/Kindeditor/%EF%BC%88CVE-2017-1002024%EF%BC%89Kindeditor%20%3C%3D4.1.11%20%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E/ https://github.com/kindsoft/kindeditor/issues/249 https://cloud.tencent.com/developer/article/2096447 https://www.anquanke.com/post/id/171422 https://zhuanlan.zhihu.com/p/57598526 https://baizesec.github.io/bylibrary/%E6%BC%8F%E6%B4%9E%E5%BA%93/02-%E7%BC%96%E8%BE%91%E5%99%A8%E6%BC%8F%E6%B4%9E/Kindeditor/kindeditor%204.1.11%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E/ https://www.exploit-db.com/exploits/38385 https://www.anquanke.com/post/id/210985 https://cn-sec.com/archives/1730145.html https://developer.aliyun.com/article/824575
Related VulnerabilitiesPoCCVE-2019-7543: KindEditor 4.1.11 - Cross-Site ScriptingKindeditor 任意文件上传漏洞PoC金和OA /c6/KindEditor1/asp/upload_json.asp 任意文件上传漏洞kindeditor编辑器4.1.10 file_manager_json.php-目录遍历kindeditor编辑器<=4.1.10 upload_json.php文件-文件上传