NA

CVE-2024-35475

Published: 22/05/2024 Updated: 22/05/2024

Vulnerability Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an malicious user to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

Github Repositories

CVE-2024-35475 Vulnerability: Cross-Site Request Forgery (CSRF) Affected Product OpenKM Community Edition Affected Version On or Before 6312 Vulnerable URL /OpenKM/admin/DatabaseQuery Description A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6312 The vulnerability exists in the /admin/DatabaseQuery endpoin