CVE 8.6 HIGH

OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery_CVE-2026-42425

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/DatabaseQuery endpoint to extract sensitive data including usernames and password hashes from the OKM_USER table, modify permissions, or delete database records.

AI Analysis

Unrestricted SQL execution vulnerability in OpenKM 6.3.12 allowing authenticated administrative users to execute arbitrary SQL statements

Basic Information

ID CVE-2026-42425
Source VulnCheck
Published May 26, 2026 at 14:08
Modified May 26, 2026 at 15:14

Affected Product

Vendor Openkm
Product OpenKM Community Edition
Affected Versions Openkm OpenKM Community Edition 0
Openkm OpenKM Professional Edition 0

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor Openkm
Product OpenKM Community Edition
Version 6.3.12

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.