Vulnerabilities > CVE-2022-2131 - XXE vulnerability in Openkm 6.3.10

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
openkm
CWE-611
critical

Summary

OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.

Vulnerable Configurations

Part Description Count
Application
Openkm
1