Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-2315

admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.118
EPSS Ranking 93.4%
CVSS Severity
CVSS v2 Score 4.0
References
Products affected by CVE-2012-2315
  • Openkm » Openkm » Version: 5.1.7
    cpe:2.3:a:openkm:openkm:5.1.7
  • Openkm » Openkm » Version: 5.1.8
    cpe:2.3:a:openkm:openkm:5.1.8


Contact Us

Shodan ® - All rights reserved