Vulnerabilities > CVE-2021-33950 - XXE vulnerability in Openkm 6.3.10

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
openkm
CWE-611

Summary

An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.

Vulnerable Configurations

Part Description Count
Application
Openkm
1