Showing 3 vulnerabilities on this page for OpenKM

Signals CISA KEV Ransomware Nuclei
OpenKM vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

CWE-352May 22, 2024
CVSS6.4v3.1EPSS0.291%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality.

CWE-79Feb 7, 2023
CVSS5.4v3.1EPSS0.506%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.

CWE-79Feb 7, 2023
CVSS5.4v3.1EPSS0.53%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX