CVE-2023-50072
MEDIUMOpenKM 7.1.40 - Authenticated Stored Cross-Site Scripting via File Note Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-50072. PoCs published by ahrixia.
AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2023-50072, demonstrating a stored XSS vulnerability in OpenKM 7.1.40 via the 'text' parameter in note uploads. It includes a detailed HTTP request example and payloads to trigger the XSS.
Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.
Exploits (1)
The repository provides a functional proof-of-concept for CVE-2023-50072, demonstrating a stored XSS vulnerability in OpenKM 7.1.40 via the 'text' parameter in note uploads. It includes a detailed HTTP request example and payloads to trigger the XSS.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N