OpenKM Vulnerabilities and Affected Products
Vulnerabilities associated with OpenKM.
Products
Clear product- OpenKM3 vulnerabilities
- OpenKM Community Edition3 vulnerabilities
- OpenKM Professional Edition3 vulnerabilities
- Document Management Community1 vulnerability
- OpenKM Document Management Community1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-35475MEDIUM | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands. CWE-352May 22, 2024 | CVSS6.4v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47414MEDIUM | If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality. CWE-79Feb 7, 2023 | CVSS5.4v3.1 | EPSS0.506% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47413MEDIUM | Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition. CWE-79Feb 7, 2023 | CVSS5.4v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |