CVE-2025-57244

Source
https://cve.org/CVERecord?id=CVE-2025-57244
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57244.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-57244
Published
2025-11-05T17:15:44.543Z
Modified
2026-03-13T03:39:49.906458Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the Email field is vulnerable when the POST request is modified to include encoded script tags, by passing frontend validation.

References

Affected packages

Git / github.com/openkm/document-management-system

Affected ranges

Type
GIT
Repo
https://github.com/openkm/document-management-system
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.3.12"
        }
    ]
}

Affected versions

Other
none
v6.*
v6.3.10
v6.3.11
v6.3.12
v6.3.3
v6.3.4
v6.3.5
v6.3.6
v6.3.7
v6.3.8
v6.3.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57244.json"