Multiple critical zero-day vulnerabilities in OpenKM Community Edition 6.3.12 and Pro Edition 7.1.47 allow remote code execution and local file inclusion via unspecified attack vectors. Exploit code is provided for authentication bypass, version detection, and LFI attacks.
| Vendor | Product | Versions |
|---|---|---|
| openkm | openkm community edition, openkm pro edition | <= 6.3.12, <= 7.1.47 |