CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-104081: KodExplorer 0 to before 4.55

CVE-2026-104081. CVSS 3.1 base score 8.1 (HIGH, Vendor/CNA).

Affected technology

KodExplorer · 0 to before 4.55
kalcaddle

Description’s affected range: before 4.55

Component: Not specified by the source
Function: within

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Authenticated attackers can upload a malicious ZIP archive with traversal sequences to overwrite arbitrary files such as core JavaScript assets, enabling stored XSS that leads to admin account takeover and subsequent remote code execution via unrestricted PHP file upload. Vendor/CNA’s CVSS 4.0 assessment (base score 7.2/10) rates confidentiality impact as none; integrity and availability impact as high.

Published

CWE
CWE-22
CCR priority
32.4 /100 (P4)
CVSS 3.1
8.1 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104081.html