CVE-2021-33950

An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openkm:openkm:6.3.10:*:*:*:community:*:*:*

History

28 Feb 2023, 20:06

Type Values Removed Values Added
CPE cpe:2.3:a:openkm:openkm:6.3.10:*:*:*:community:*:*:*
References (MISC) https://github.com/openkm/document-management-system/issues/287 - (MISC) https://github.com/openkm/document-management-system/issues/287 - Issue Tracking
References (MISC) https://github.com/openkm/document-management-system/pull/288 - (MISC) https://github.com/openkm/document-management-system/pull/288 - Patch
References (MISC) https://github.com/openkm/document-management-system/commit/ce1d82329615aea6aa9f2cc6508c1fe7891e34b5 - (MISC) https://github.com/openkm/document-management-system/commit/ce1d82329615aea6aa9f2cc6508c1fe7891e34b5 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Openkm openkm
Openkm
CWE CWE-611

17 Feb 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-17 18:15

Updated : 2023-12-10 14:48


NVD link : CVE-2021-33950

Mitre link : CVE-2021-33950

CVE.ORG link : CVE-2021-33950


JSON object : View

Products Affected

openkm

  • openkm
CWE
CWE-611

Improper Restriction of XML External Entity Reference