VYPR
High severity8.5NVD Advisory· Published Jul 25, 2022· Updated Jun 17, 2026

CVE-2022-2131

CVE-2022-2131

Description

OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:openkm:openkm:*:*:*:*:community:*:*:*
    Range: <=6.3.10
  • Range: <=6.3.10
  • OpenKM/OpenKM Document Management Communityv5
    Range: 6.3.10

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.