Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 17 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:cksource:ckfinder:*:*:*:*:*:asp.net:*:* |
Fri, 05 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 05 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided. | |
| First Time appeared |
Cksource
Cksource ckfinder |
|
| Weaknesses | CWE-23 | |
| CPEs | cpe:2.3:a:cksource:ckfinder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cksource
Cksource ckfinder |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-05T17:20:03.650Z
Reserved: 2025-12-05T00:00:00.000Z
Link: CVE-2016-20023
Updated: 2025-12-05T17:08:07.689Z
Status : Analyzed
Published: 2025-12-05T06:16:03.720
Modified: 2025-12-17T16:09:10.830
Link: CVE-2016-20023
No data.
OpenCVE Enrichment
No data.