Uploaded image for project: 'ZK CKeditor'
  1. ZK CKeditor
  2. ZKCK-34

Zkoss CKEditor vulnerable to file browsing

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • 4.7.0.0
    • None
    • None

      ZK CKEditor allows file browsing for arbitrary folders.

      The attacker can find out filenames on the server, discover folders and other information. Even though in code the "WEB-INF" and "META-INF" paths are "ignored", if they are set as browsing roots, their content is showed*.

      The parameter "Type" needs to be changed to "Files", parameter "url" denotes the folder within the webroot.

      See live demo here:
      https://www.zkoss.org/zkdemo/zkau/web/bb1940f4/ckez/html/browse.zul?Type=Files&url=/WEB-INF/&CKEditor=aLGPn-cnt&CKEditorFuncNum=2&langCode=en

      • - limited to extensions as can be seen in the source of ZK CKEditor - .jsp .php etc.

            rudyhuang rudyhuang
            oskarsv oskarsv
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 hour
                1h