CVE-2025-63830 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.
Medium CVSS: 6.1

CVE-2025-63830

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.
Vendor
Cksource
Product
Ckfinder
CWE
CWE-79
Yayın Tarihi
2025-11-14 18:15:51
Güncelleme
2025-11-19 13:20:11
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar