CVE-2016-20023
5MEDIUM
What is CVE-2016-20023?
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
Affected Version(s)
CKFinder 2 < 2.5.0.1
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
CKFinder 2 < 2.5.0.1