Vulnerabilities > CVE-2022-2131 - XXE vulnerability in Openkm 6.3.10
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |