OpenKM是西班牙OpenKM公司的一套文档管理系统。该系统提供版本控制、文件历史记录和文件共享等功能。 OpenKM 6.3.12版本存在路径遍历漏洞,该漏洞源于管理脚本接口中存在本地文件包含漏洞,可能导致认证管理员通过fsPath参数读取任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Openkm | OpenKM Community Edition | ≤ 6.3.12 |
affected |
| Openkm | OpenKM Professional Edition | ≤ 7.1.47 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openkm | OpenKM Community Edition | 0 ~ 6.3.12 | - |
|
| Openkm | OpenKM Professional Edition | 0 ~ 7.1.47 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42785 | 7.2 HIGH | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting |
| CVE-2026-42425 | 7.2 HIGH | OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery |
No comments yet