[POC] XSS OpenKM CVE-2023-50072 Exploit
by Farfallaiero - Friday December 22, 2023 at 06:36 PM
#1
A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.


https://github.com/ahrixia/CVE-2023-50072

Quick shodan search and test on the vuln version i found seems legit - exploit says you got to be authenticated actor though which it didnt seem to be an issue with my test

[Image: IcoXNAG.png]
0D|nS3c
Reply
#2
don't no why someone have to pay 8 credit when it's all for free

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Sale of public leaks + attempted scam and manipulation. Shame. | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
(Dec 22, 2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?
0D|nS3c
Reply
#4
(Dec 22, 2023, 06:48 PM)Farfalla Wrote:
(Dec 22, 2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?

Thanks for fixing it fart man Big Grin

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Sale of public leaks + attempted scam and manipulation. Shame. | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#5
(Dec 22, 2023, 06:54 PM)MI6ixy Wrote:
(Dec 22, 2023, 06:48 PM)Farfalla Wrote:
(Dec 22, 2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?

Thanks for fixing it fart man Big Grin

welcome my negro
0D|nS3c
Reply
#6
(Dec 22, 2023, 07:00 PM)Farfalla Wrote:
(Dec 22, 2023, 06:54 PM)MI6ixy Wrote:
(Dec 22, 2023, 06:48 PM)Farfalla Wrote:
(Dec 22, 2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?

Thanks for fixing it fart man Big Grin

welcome my negro

Ok and add me on jabber so we can nig nig around my nigga Big Grin

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Sale of public leaks + attempted scam and manipulation. Shame. | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#7
hey what about exploit for firewall bypass and get admin access?

have you ever looked for an exploit to bypass firewalls like Fortinet?
Reply
#8
(Dec 22, 2023, 06:36 PM)Farfalla Wrote: A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.


https://github.com/ahrixia/CVE-2023-50072

Quick shodan search and test on the vuln version i found seems legit - exploit says you got to be authenticated actor though which it didnt seem to be an issue with my test 

[Image: IcoXNAG.png]

nice work my friend Exclamation
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  New Zer0 Day Wordpress A3g00n 83 4,084 May 11, 2026, 08:17 PM
Last Post: j4ng0
  {SECRET} DATABASE OF EXPLOITS lulagain 441 28,127 May 11, 2026, 05:41 PM
Last Post: chiki
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 69 3,731 May 11, 2026, 03:55 PM
Last Post: fkmonkey
  CVE-2024-32002 RCE PoC HA_twck 2 573 May 11, 2026, 01:33 PM
Last Post: newxiao1
  Cisco Secure Firewall Management Center(CVE-2026-20131) DirtyEra 0 143 May 11, 2026, 01:40 AM
Last Post: DirtyEra

Forum Jump:


 Users browsing this forum: 1 Guest(s)