[POC] XSS OpenKM CVE-2023-50072 Exploit
by Farfallaiero - Friday December 22, 2023 at 06:36 PM
#1
A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.


https://github.com/ahrixia/CVE-2023-50072

Quick shodan search and test on the vuln version i found seems legit - exploit says you got to be authenticated actor though which it didnt seem to be an issue with my test

[Image: IcoXNAG.png]
0D|nS3c
Reply
#2
don't no why someone have to pay 8 credit when it's all for free
Ban reason: Sale of public leaks + attempted scam and manipulation. Shame. | https://breachforums.sb/Forum-Ban-Appeals if you feel this is incorrect. (Permanent)
Reply
#3
(12-22-2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?
0D|nS3c
Reply
#4
(12-22-2023, 06:48 PM)Farfalla Wrote:
(12-22-2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?

Thanks for fixing it fart man Big Grin
Ban reason: Sale of public leaks + attempted scam and manipulation. Shame. | https://breachforums.sb/Forum-Ban-Appeals if you feel this is incorrect. (Permanent)
Reply
#5
(12-22-2023, 06:54 PM)MI6ixy Wrote:
(12-22-2023, 06:48 PM)Farfalla Wrote:
(12-22-2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?

Thanks for fixing it fart man Big Grin

welcome my negro
0D|nS3c
Reply
#6
(12-22-2023, 07:00 PM)Farfalla Wrote:
(12-22-2023, 06:54 PM)MI6ixy Wrote:
(12-22-2023, 06:48 PM)Farfalla Wrote:
(12-22-2023, 06:39 PM)MI6ixy Wrote: don't no why someone have to pay 8 credit when it's all for free

wait this is behind a paywall?

Thanks for fixing it fart man Big Grin

welcome my negro

Ok and add me on jabber so we can nig nig around my nigga Big Grin
Ban reason: Sale of public leaks + attempted scam and manipulation. Shame. | https://breachforums.sb/Forum-Ban-Appeals if you feel this is incorrect. (Permanent)
Reply
#7
hey what about exploit for firewall bypass and get admin access?

have you ever looked for an exploit to bypass firewalls like Fortinet?
Reply
#8
(12-22-2023, 06:36 PM)Farfalla Wrote: A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on a file which acts as a stored XSS payload. Any user who opens the note of a document file will trigger the XSS.


https://github.com/ahrixia/CVE-2023-50072

Quick shodan search and test on the vuln version i found seems legit - exploit says you got to be authenticated actor though which it didnt seem to be an issue with my test 

[Image: IcoXNAG.png]

nice work my friend Exclamation
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  new wordpress website takeover vuln (video + poc ) zinzeur 312 27,277 03-28-2026, 02:43 AM
Last Post: toshi99
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 106 13,201 02-10-2026, 03:34 PM
Last Post: birhikayemvar
  Ban Any Discord Exploit PhineasFisher 6 295 02-08-2026, 11:49 PM
Last Post: skype
  Cool Remote Patching ETW/Amsi PoC pepeloco 6 2,092 02-08-2026, 07:58 AM
Last Post: zeroday99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 73 02-07-2026, 03:32 PM
Last Post: cysc



 Users browsing this thread: 1 Guest(s)