CVE-2022-2131 Information

Description

OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags allowing an attacker to perform a XML external entity injection attack.

Reference

https://www.incibe-cert.es/en/early-warning/security-advisories/openkm-xxe-injection

Share on: