Impact
KodExplorer before version 4.55 allows authenticated users to upload ZIP files. The unzip_pre_name() function performs a single non‑recursive str_replace() sanitization pass that cannot block filenames containing patterns such as ".….//", enabling path traversal when the archive is extracted with PclZip’s extract() call that lacks the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. An attacker can craft a ZIP with traversal sequences to overwrite critical files like core JavaScript assets, resulting in stored cross‑site scripting that permits an attacker to hijack an administrator account. Once an admin account is compromised, the attacker can upload arbitrary PHP files to execute remote code.
Affected Systems
This issue affects the KodExplorer web application distributed by kalcaddle. All releases prior to version 4.55 are vulnerable. The vulnerability is present in the app/function/helper.function.php file of KodExplorer and the KodArchive.class.php extractor.
Risk and Exploitability
The CVSS score of 7.2 marks a high‑severity vulnerability, while the EPSS score is not available and the issue is not listed in the CISA KEV catalog. The vulnerability requires authenticated access to the application, but authenticated users can perform file uploads. Successful exploitation would give an attacker remote code execution capabilities once the prerequisite of admin takeover is achieved. Because the flaw relies purely on application‑level oversight, it is likely to be exploitable on any publicly reachable instance that has not applied the 4.55 patch or re‑implemented safe extraction measures.
OpenCVE Enrichment