If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-50177 | If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality. |
Tue, 25 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2025-03-25T14:08:10.227Z
Reserved: 2022-12-14T22:27:49.186Z
Link: CVE-2022-47414
Updated: 2024-08-03T14:55:07.965Z
Status : Modified
Published: 2023-02-07T22:15:10.733
Modified: 2025-03-25T15:15:17.250
Link: CVE-2022-47414
No data.
OpenCVE Enrichment
No data.
EUVD