CVE-2012-2315 describes a privilege enforcement vulnerability in OpenKM 5.1.7 and earlier versions, specifically within the admin/Auth component. This flaw allows remote authenticated users to elevate privileges by assigning administrator roles to arbitrary users via the userEdit action. The vulnerability has a CVSS score of 4.0, indicating a network-based attack with low complexity, requiring authentication, and resulting in partial integrity impact. While no active exploitation or Metasploit/Nuclei modules are reported, an ExploitDB entry (EDB-18888) exists for a command execution vulnerability in the same product version, though not directly for this specific CVE. Community discussion and media coverage for CVE-2012-2315 are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1.7CPE matchmatch criteria | cpe:2.3:a:openkm:openkm:*:*:*:*:*:*:*:* | ||
5.1.8CPE matchmatch criteria | cpe:2.3:a:openkm:openkm:5.1.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.