Description

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

INFO

Published Date :

2025-12-05T00:00:00.000Z

Last Modified :

2025-12-05T17:20:03.650Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2016-20023 vulnerability.

Vendors Products
Cksource
  • Ckfinder
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2016-20023.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact