EIP-2026-109011
PRE-CVEKindEditor - Multiple Arbitrary File Upload Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109011. PoCs published by KedAns-Dz.
AI-analyzed exploit summary The exploit demonstrates a file upload vulnerability in KindEditor 4.1.5, allowing arbitrary file uploads via a crafted POST request to the upload_json.php endpoint. The provided PHP script and HTML/JavaScript example show how to bypass insufficient input sanitization to upload malicious files.
Description
KindEditor - Multiple Arbitrary File Upload Vulnerabilities
Exploits (1)
The exploit demonstrates a file upload vulnerability in KindEditor 4.1.5, allowing arbitrary file uploads via a crafted POST request to the upload_json.php endpoint. The provided PHP script and HTML/JavaScript example show how to bypass insufficient input sanitization to upload malicious files.