OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2022-07-25 15:15
Updated : 2022-07-25 15:25
NVD link : CVE-2022-2131
Mitre link : CVE-2022-2131
JSON object : View
Products Affected
No product.
CWE
No CWE.
