CVE-2024-35475: Openkm
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.
Affected products
- Openkm Openkm: up to and including 6.3.12
Published 2024-05-22. Last modified 2026-06-17.