Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CKEditor / FCKeditor 'uploadtest.html' SSRF Vulnerability

Information

Severity

Severity

Medium

Family

Family

Web application abuses

CVSSv2 Base

CVSSv2 Base

4.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

Solution Type

Solution Type

Mitigation

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

The 'uploadtest.html' file shipped with CKEditor / FCKeditor is prone to a server-side request forgery (SSRF) vulnerability.

Affected Software

Affected Software

CKEditor version 3.x and FCKeditor version 2.x are known to ship the vulnerable file.

Detection Method

Detection Method

Checks via a crafted HTTP GET request if the affected uploadtest.html file exists on the target host.

Solution

Solution

Remove the affected file from the target host. Note: CKEditor 4.0+ doesn't ship this file anymore but it still might exist on the file system if it wasn't removed during the update.