PT-2022-25345 · Openkm · Openkm

Monkiki

·

Published

2022-09-09

·

Updated

2022-09-14

·

CVE-2022-40317

CVSS v3.1
5.4
VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenKM version 6.3.11
Description The issue allows stored XSS related to the javascript: substring in an A element. This could potentially lead to malicious script execution when a user interacts with the affected element.
Recommendations For OpenKM version 6.3.11, consider disabling the use of javascript: substrings in A elements until a patch is available. Restrict access to areas where such substrings could be injected to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40317

Affected Products

Openkm