296,349
Total vulnerabilities in the database
Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary code via the script parameter to admin/scripting.jsp.
Software | From | Fixed in |
---|---|---|
openkm / openkm | 5.1.7 | 5.1.7.x |
openkm / openkm | 5.1.8 | 5.1.8.x |