Stored Cross-Site Scripting Vulnerability in OpenKM Community Edition
CVE-2025-57244
5.4MEDIUM
What is CVE-2025-57244?
OpenKM Community Edition 6.3.12 contains a vulnerability that allows for stored cross-site scripting (XSS) within the user account creation interface. This vulnerability arises from the system's inability to correctly validate user input, as the Name field fails to sanitize script tags. Additionally, the Email field is susceptible when POST requests are manipulated to include encoded script tags, bypassing front-end validation mechanisms. Attackers can exploit this flaw to execute malicious scripts within the user's browser context, potentially leading to data theft or session hijacking.
