MEDIUM
kalcaddle kodbox fileGet Endpoint editor.class.php PathDriverUrl server-side request forgery
Published Mar 23, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.35%
Description
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.64StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14432 Advisory
- https://vuldb.com/submit/775467 third-party-advisory
- https://vuldb.com/vuln/352425 vdb-entrytechnical-description
- https://vuldb.com/vuln/352425/cti signaturepermissions-required
- https://vulnplus-note.wetolink.com/share/UTZQq38f9VyI broken-linkexploit
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14432 | Advisory | |
| https://vuldb.com/submit/775467 | third-party-advisory | |
| https://vuldb.com/vuln/352425 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/352425/cti | signaturepermissions-required | |
| https://vulnplus-note.wetolink.com/share/UTZQq38f9VyI | broken-linkexploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 23, 2026
Updated Apr 18, 2026
Reserved Mar 22, 2026
Link CVE-2026-4589
CISA Vulnrichment
Updated Mar 23, 2026
ENISA EUVD
EUVD-2026-14432 Assigner VulDB
Published Mar 23, 2026
Updated Apr 18, 2026
Exploited since n/a
Link EUVD-2026-14432