Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-35475

EPSS 0.20% · P42
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-35475

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenKM 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenKM是西班牙OpenKM公司的一套文档管理系统。该系统提供版本控制、文件历史记录和文件共享等功能。 OpenKM 6.3.12及之前版本存在安全漏洞,该漏洞源于组件/admin/DatabaseQuery存在跨站请求伪造(CSRF)漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2024-35475

#POC DescriptionSource LinkShenlong Link
1Nonehttps://github.com/carsonchan12345/CVE-2024-35475POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-35475

登录查看更多情报信息。

Same Patch Batch · n/a · 2024-05-22 · 34 CVEs total

CVE-2024-360778.8 HIGHQlik Sense 安全漏洞
CVE-2024-29392Silverpeas 安全漏洞
CVE-2024-33222ASUS ATSZIO Driver 安全漏洞
CVE-2024-33223ASUS GPUTweak II 安全漏洞
CVE-2024-33224Realtek Semiconductor Corp Realtek lO Driver 安全漏洞
CVE-2024-33225Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver 安全漏洞
CVE-2024-33226Wistron Corporation TBT Force Power Control 安全漏洞
CVE-2024-33227Nicomsoft WinI2C/DDC 安全漏洞
CVE-2024-33228Insyde Software Corp SEG Windows Driver 安全漏洞
CVE-2024-35362Ecshop 安全漏洞
CVE-2024-33221ASUS BIOS Flash Driver 安全漏洞
CVE-2024-34448Ghost Foundation Ghost 安全漏洞
CVE-2024-29421xmedcon 安全漏洞
CVE-2024-31617Litespeed Technologie OpenLiteSpeed 安全漏洞
CVE-2024-25738Open Library Foundation VuFind 安全漏洞
CVE-2024-25737Open Library Foundation VuFind 安全漏洞
CVE-2024-35627TileServer GL 安全漏洞
CVE-2024-35551idccms 安全漏洞
CVE-2024-33220ASUS AI Suite 安全漏洞
CVE-2024-33219ASUS SABERTOOTH X99 Driver 安全漏洞

Showing top 20 of 34 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2024-35475

No comments yet


Leave a comment