S4E just found a high top 10 tcp port service scan
medium·Web Vulnerabilities·Updated May 21, 2025

CVE-2021-36646 Scanner

CVE-2021-36646 Scanner - Cross-Site Scripting (XSS) vulnerability in KodExplorer

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-36646
6.1
CVSS

A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

KodExplorer is a web-based file management system used by various businesses and individuals for personal cloud disc management. It allows users to view, edit, and share files online, providing functionalities similar to a proprietary cloud storage solution. KodExplorer supports a variety of file types and includes features like user permission management, making it a choice for collaborative environments. Companies use KodExplorer to streamline file sharing processes and enhance productivity in virtual workspaces.

The vulnerability detected in KodExplorer is a Cross-Site Scripting (XSS) vulnerability. This type of vulnerability can allow attackers to inject malicious scripts into web pages viewed by other users. If successfully exploited, it enables attackers to execute malicious JavaScript within the context of another user's session. This scenario is particularly dangerous as it can be used to steal user credentials, session tokens, or other sensitive information.

The KodExplorer vulnerability resides in its file view functionality, specifically in the app/template/api/view.html file. The vulnerability is triggered when user-supplied input in the 'path' parameter is reflected back in the web page response without adequate sanitization or encoding. This flaw allows attackers to inject and execute arbitrary JavaScript code in the user's browser, potentially leading to hijacked user sessions or unauthorized actions.

Exploiting this vulnerability could lead attackers to conduct phishing attacks, redirect users to malicious sites, or perform unauthorized actions on behalf of the affected users. The implications also include heightened risks of data leakage or corruption, as attackers could access sensitive data if permissions are insufficiently restricted. Organizations using KodExplorer without applying security updates are particularly vulnerable to these exploits.

REFERENCES

Solution Advice
  • Upgrade to the latest version of KodExplorer that addresses this vulnerability.
  • Implement proper input validation to ensure that user inputs are correctly sanitized before processing.
  • Employ output encoding measures to ensure any user-supplied data is safely integrated into web pages.
  • Regularly review your web application security configurations and update as necessary to follow best practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.