Kiteworks Mft是美国Kiteworks公司的一个安全管理内部和外部数据传输的软件。 Kiteworks Mft 9.1.0之前版本存在跨站请求伪造漏洞,该漏洞源于管理员可能被诱导访问特制页面,导致日志信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kiteworks | security-advisories | < 9.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-53899 | 7.2 HIGH | Kiteworks MFT is vulnerable to an Incorrectly Specified Destination in a Communication Cha |
| CVE-2025-53896 | 7.1 HIGH | Kiteworks MFT is vulnerable to Insufficient Session Expiration |
| CVE-2025-53900 | 6.5 MEDIUM | Kiteworks MFT has a Privilege Defined With Unsafe Actions |
| CVE-2025-53939 | 6.3 MEDIUM | Kiteworks Core is vulnerable to Improper Input Validation |
No comments yet