PT-2022-24987 · Openkm · Openkm
CVSS v3.1
2.6
Low
| Vector | AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenKM versions up to 6.3.11
Description
A vulnerability was found in the function
getFileExtension of the file src/main/java/com/openkm/util/FileUtils.java. The manipulation leads to an insecure temporary file.Recommendations
For OpenKM versions up to 6.3.11, upgrade to version 6.3.12 to address this issue. As a temporary workaround, consider restricting the use of the
getFileExtension function until the upgrade is applied.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openkm