CVE-2026-4830

A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

30 Mar 2026, 13:26

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad en kalcaddle kodbox 1.64. Este problema afecta a la función Add del archivo app/controller/explorer/userShare.class.php del componente Gestor de Compartición Pública. Dicha manipulación conduce a una carga sin restricciones. El ataque puede ejecutarse de forma remota. Este ataque se caracteriza por una alta complejidad. La explotabilidad se evalúa como difícil. El exploit está disponible públicamente y podría ser utilizado. Se contactó con el proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.

26 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 01:16

Updated : 2026-06-17 10:57


NVD link : CVE-2026-4830

Mitre link : CVE-2026-4830

CVE.ORG link : CVE-2026-4830


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type