Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-2316

Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary code via the script parameter to admin/scripting.jsp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 87.0%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2012-2316
  • Openkm » Openkm » Version: 5.1.7
    cpe:2.3:a:openkm:openkm:5.1.7
  • Openkm » Openkm » Version: 5.1.8
    cpe:2.3:a:openkm:openkm:5.1.8


Contact Us

Shodan ® - All rights reserved