Stored Cross-Site Scripting Vulnerability in OpenKM Community Edition
CVE-2025-57244

5.4MEDIUM

Key Information:

Vendor

OpenKM

Vendor
CVE Published:
5 November 2025

What is CVE-2025-57244?

OpenKM Community Edition 6.3.12 contains a vulnerability that allows for stored cross-site scripting (XSS) within the user account creation interface. This vulnerability arises from the system's inability to correctly validate user input, as the Name field fails to sanitize script tags. Additionally, the Email field is susceptible when POST requests are manipulated to include encoded script tags, bypassing front-end validation mechanisms. Attackers can exploit this flaw to execute malicious scripts within the user's browser context, potentially leading to data theft or session hijacking.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.