S4E just found a medium-severity finding from cookies without secure attribute security misconfiguration scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-40359 Scanner

CVE-2022-40359 scanner - Cross-Site Scripting (XSS) vulnerability in Kae's File Manager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-40359
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Kae's File Manager (KFM) is a web-based tool that allows users to upload, manage and organize files on their website. It is a popular file manager solution for website owners and developers due to its simple user interface and ease of use. With KFM, users can easily upload files, rename, delete, and move them around.

However, KFM was recently discovered to have a vulnerability code that is CVE-2022-40359. The vulnerability can be exploited by attackers through a crafted GET request to /kfm/index.php. This allows the attacker to inject and execute malicious code into the website, which can be used to steal sensitive information, gain unauthorized access to the website, and even take full control of the website.

When this vulnerability is exploited, it can lead to serious consequences for website owners. The attacker can easily steal sensitive data such as usernames, passwords, and other confidential information. They can also use the access they gain to launch attacks on other systems, distribute malware, and commit other cybercrimes. It is, therefore, vital for website owners to take steps to protect their websites from this vulnerability.

In conclusion, it is crucial for website owners to take the necessary precautions to protect their digital assets from vulnerabilities such as the one found in Kae's File Manager. By using pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets. This includes receiving real-time alerts and detailed analysis of vulnerabilities as they are discovered. By staying informed and taking proactive measures, website owners can prevent cyber-attacks and safeguard their data from malicious actors.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update to the latest version of KFM to patch the vulnerability
  • Add a web application firewall (WAF) to provide additional protection against the vulnerability
  • Monitor website traffic for malicious activity using a security solution
  • Apply strict input validation to prevent malicious code injection
  • Implement secure coding practices and limit user permissions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.