CVE-2026-104081
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-104081, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. Authenticated attackers can upload a malicious ZIP archive with traversal sequences to overwrite arbitrary files such as core JavaScript assets, enabling stored XSS that leads to admin account takeover and subsequent remote code execution via unrestricted PHP file upload.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kalcaddle KodExplorer 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

KodExplorer before version 4.55 has a path traversal flaw in the unzip_pre_name() function. This flaw allows attackers to bypass a single sanitization step using crafted filenames like '....//'. When combined with PclZip's extract() function lacking directory restrictions, it enables overwriting arbitrary files such as JavaScript assets. This can lead to stored cross-site scripting (XSS), admin account takeover, and remote code execution via unrestricted PHP file uploads.

Detection Guidance

Check for uploaded ZIP archives with traversal sequences like ....// in filenames. Inspect app/function/helper.function.php for the unzip_pre_name() function and verify if PclZip's extract() lacks PCLZIP_OPT_EXTRACT_DIR_RESTRICTION. Look for unexpected file overwrites in core JavaScript assets or PHP files.

Impact Analysis

Authenticated attackers can exploit this to overwrite critical files, inject malicious scripts, or execute arbitrary code on your system. This could result in unauthorized access, data theft, or complete system compromise if PHP files are uploaded and executed.

Compliance Impact

This vulnerability could lead to unauthorized file access and stored XSS, potentially exposing sensitive data. GDPR requires protecting personal data, and HIPAA mandates securing health information. A successful exploit may violate these regulations by enabling data breaches or unauthorized access to protected assets.

Mitigation Strategies

Upgrade KodExplorer to version 4.55 or later. Remove or restrict write permissions to directories where user uploads are stored. Implement stricter input validation for uploaded filenames. Disable PHP file uploads if not required. Monitor for unauthorized file modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104081. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart