CVE-2012-2315: Openkm

Medium severity, CVSS 4.0. EPSS: 6.2% chance of exploitation in the next 30 days.

admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.

Affected products

  • Openkm Openkm: up to and including 5.1.7; version 5.1.8 only

Published 2012-09-09. Last modified 2026-06-16.