8.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/DatabaseQuery endpoint to extract sensitive data including usernames and password hashes from the OKM_USER table, modify permissions, or delete database records.
AI Analysis
Unrestricted SQL execution vulnerability in OpenKM 6.3.12 allowing authenticated administrative users to execute arbitrary SQL statements
Basic Information
ID
CVE-2026-42425
Source
VulnCheck
Published
May 26, 2026 at 14:08
Modified
May 26, 2026 at 15:14
Affected Product
Vendor
Openkm
Product
OpenKM Community Edition
Affected Versions
Openkm OpenKM Community Edition 0
Openkm OpenKM Professional Edition 0
Openkm OpenKM Professional Edition 0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Openkm
Product
OpenKM Community Edition
Version
6.3.12
References
- www.exploit-db.com /exploits/52520
- www.openkm.com /
- hub.docker.com /r/openkm/openkm-ce
- terrasystemlabs.com /post
- github.com /terrasystemlabs/Exploits/tree/main/OpenKM-Exploits
- github.com /terrasystemlabs/Exploits/tree/main/OpenKM-Exploits/nuclei-templates/openkm-sql-database-query
- www.vulncheck.com /advisories/openkm-unrestricted-sql-execution-via-databasequery