Vulnerability Description
OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openkm | Openkm | 6.3.10 |
Related Weaknesses (CWE)
References
- https://docs.openkm.com/kcenter/view/okm-6.3-com/migration-guide.htmlRelease NotesVendor Advisory
- https://github.com/openkm/document-management-system/issues/278Issue TrackingPatchThird Party Advisory
- https://www.incibe-cert.es/en/early-warning/security-advisories/openkm-document-Third Party Advisory
- https://docs.openkm.com/kcenter/view/okm-6.3-com/migration-guide.htmlRelease NotesVendor Advisory
- https://github.com/openkm/document-management-system/issues/278Issue TrackingPatchThird Party Advisory
- https://www.incibe-cert.es/en/early-warning/security-advisories/openkm-document-Third Party Advisory
FAQ
What is CVE-2021-3628?
CVE-2021-3628 is a vulnerability with a CVSS score of 4.6 (MEDIUM). OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid par...
How severe is CVE-2021-3628?
CVE-2021-3628 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3628?
Check the references section above for vendor advisories and patch information. Affected products include: Openkm Openkm.