CVE-2022-47414

Publication date

2023-02-07 21:41:39

Family

rapid7

State

PUBLISHED

Description

If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality.