CVE-2012-2315

OpenKM <5.1.8-2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-2315.

AI-analyzed exploit summary This exploit demonstrates a CSRF-based OS command execution vulnerability in OpenKM Document Management System 5.1.7. It leverages the lack of anti-CSRF tokens in the administrative interface to execute arbitrary commands via the scripting.jsp endpoint.

Description

admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.

Exploits (1)

exploitdb WORKING POC
webappsjsp
https://www.exploit-db.com/exploits/18888

This exploit demonstrates a CSRF-based OS command execution vulnerability in OpenKM Document Management System 5.1.7. It leverages the lack of anti-CSRF tokens in the administrative interface to execute arbitrary commands via the scripting.jsp endpoint.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: OpenKM Document Management System 5.1.7
Auth required
Prerequisites: Administrator access to OpenKM · Victim must be lured to a malicious page or URL
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (11)

Core 11
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/23/6
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/04/2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51250
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-01/0007.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/23/8
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-01/0021.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/04/13
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72112
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/27/6
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47424
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/78105

Scores

EPSS 0.0622
EPSS Percentile 92.6%

Details

CWE
CWE-264
Status published
Products (2)
openkm/openkm 5.1.8
openkm/openkm < 5.1.7
Published Sep 09, 2012
Tracked Since Feb 18, 2026