CVE-2023-6851
CVE-2023-6851 is a medium-severity vulnerability in Kodcloud Kodexplorer with a CVSS 3.x base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Medium (CVSS 3.x base score 6.3)
- CVSS v2: 6.5
- EPSS exploit prediction: 1% (57th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Kodcloud Kodexplorer
- Published:
- Last modified:
Description
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the file plugins/zipView/app.php of the component ZIP Archive Handler. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.52.01 is able to address this issue. The patch is named 5cf233f7556b442100cf67b5e92d57ceabb126c6. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248219.
Frequently asked questions
- What is CVE-2023-6851?
- A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the file plugins/zipView/app.php of the component ZIP Archive Handler. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.52.01 is able to address this issue. The patch is named 5cf233f7556b442100cf67b5e92d57ceabb126c6. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248219.
- How severe is CVE-2023-6851?
- CVE-2023-6851 has a CVSS 3.x base score of 6.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2023-6851 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (57th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-6851?
- CVE-2023-6851 affects Kodcloud Kodexplorer. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-6851?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-6851 published?
- CVE-2023-6851 was published on 2023-12-16 and last updated on 2026-06-17.
References
- https://github.com/kalcaddle/KodExplorer/commit/5cf233f7556b442100cf67b5e92d57ceabb126c6
- https://github.com/kalcaddle/KodExplorer/releases/tag/4.52.01
- https://note.zhaoj.in/share/D44UjzoFXYfi
- https://vuldb.com/?ctiid.248219
- https://vuldb.com/?id.248219
Affected products (1)
- cpe:2.3:a:kodcloud:kodexplorer:*:*:*:*:*:*:*:*
More vulnerabilities in Kodcloud Kodexplorer
- CVE-2022-46154 — High (CVSS 8.6): Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not…
- CVE-2023-6853 — Medium (CVSS 6.3): A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability…
- CVE-2023-6852 — Medium (CVSS 6.3): A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown…
- CVE-2023-6850 — Medium (CVSS 6.3): A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability…
- CVE-2025-34504 — Medium (CVSS 6.1): KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the…
- CVE-2023-49489 — Medium (CVSS 6.1): Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive…
All CVEs affecting Kodcloud Kodexplorer →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…