CVE-2022-2131
OpenKM XXE Injection
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.5EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
25 Jul 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Affected products
OpenKM · OpenKM Document Management CommunityWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →