Impact
Kiteworks Core prior to 9.5.1 contains a content injection vulnerability in its PDF viewer. A URL parameter controlling the document source is insufficiently validated, permitting a maliciously crafted link to load a remote document under the same origin as the legitimate application. The result is that attackers can embed malicious links within the displayed content, increasing the credibility of phishing attacks. The CWE identifier for this weakness is 601, which denotes improper validation of user supplied data used for authority decisions.
Affected Systems
All installations of Kiteworks Core running versions older than 9.5.1 are affected. The problem arises wherever the PDF viewer component accepts any URL without verifying that it points to an internal, trusted source.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an attacker can influence the victim via a malicious link that opens the PDF viewer. Exploitation requires the victim to open the infected document; no elevated privileges are necessary. Because the vulnerability increases the credibility of phishing attempts, its impact is primarily on user trust and potential credential compromise rather than direct system compromise.
OpenCVE Enrichment