Unrated severityNVD Advisory· Published Sep 9, 2012· Updated Apr 29, 2026
CVE-2012-2315
CVE-2012-2315
Description
admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/47424nvdVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2012-01/0007.htmlnvd
- archives.neohapsis.com/archives/bugtraq/2012-01/0021.htmlnvd
- osvdb.org/78105nvd
- www.openwall.com/lists/oss-security/2012/03/23/6nvd
- www.openwall.com/lists/oss-security/2012/03/23/8nvd
- www.openwall.com/lists/oss-security/2012/04/27/6nvd
- www.openwall.com/lists/oss-security/2012/05/04/13nvd
- www.openwall.com/lists/oss-security/2012/05/04/2nvd
- www.securityfocus.com/bid/51250nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/72112nvd
News mentions
0No linked articles in our index yet.