What the vulnerability does

01Description

If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality.

Key dates

02Disclosure timeline

February 7, 2023 CVE published
March 25, 2025 Record updated