Impact
Kiteworks Core before version 9.5.0 contains a stored Cross‑site Scripting flaw that allows an authenticated user to embed malicious JavaScript in shared content. When another authenticated user previews the content, the script runs in their browser, giving the attacker the ability to hijack the victim’s session and potentially take over the account. This vulnerability is a classic example of CWE‑79, where unsanitized input is reflected into the page without proper encoding.
Affected Systems
The affected product is Kiteworks Core. All installations of Kiteworks Core earlier than version 9.5.0 are vulnerable; no specific sub‑versions are listed, so any version before the 9.5.0 release is considered at risk.
Risk and Exploitability
The vulnerability scores an 8.7 on the CVSS scale, indicating high severity. EPSS information is not available, so the current exploitation probability cannot be quantified, but the attack requires an authenticated user to perform the initial action and another user to preview the content. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no widespread active exploitation is confirmed. Nevertheless, the combination of high impact, potential for widespread compromise, and the lack of a publicly available mitigated version makes this a significant risk for organizations still running affected Kiteworks Core instances.
OpenCVE Enrichment