Description
OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
This vulnerability has been solved by OpenKM in it´s 6.3.11 version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-26931 | OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-17T04:29:31.347Z
Reserved: 2021-06-29T00:00:00.000Z
Link: CVE-2021-3628
No data.
Status : Modified
Published: 2021-08-30T18:15:09.753
Modified: 2024-11-21T06:22:01.003
Link: CVE-2021-3628
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD