Impact
The vulnerability in Kiteworks Core is a stored cross‑site scripting (XSS) flaw rated at CVSS‑8.1. According to the advisory, an administrator holding only a single, narrowly scoped delegated permission can embed crafted JavaScript into content that is later rendered in a System Administrator’s browser when they view the affected page. The injected script runs in the authenticated administrator session, enabling the attacker to create new administrative accounts and thereby gain full control of the tenant. This scenario is aligned with CWE‑79, which concerns insufficient input validation or output encoding. Based on the description, it is inferred that the malicious script execution grants the attacker the same privileges as the System Administrator, allowing them to perform tenant‑wide administrative actions.
Affected Systems
The vulnerability affects Kiteworks Core. No specific version range is listed in the advisory. Based on the lack of version information, it is inferred that all currently deployed instances of Kiteworks Core may be vulnerable until a vendor patch is released.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers need only the ability to store content with a scoped delegated permission; once they do, the stored malicious content is executed in an admin’s browser, giving the attacker full administrative privileges. Based on the description, it is inferred that the attacker only needs to perform content submission, after which the malicious payload will be executed during the administrator’s session. The lack of a publicly available exploit reduces immediate widespread risk, but the potential for complete tenant compromise warrants urgent action.
OpenCVE Enrichment