Impact
A stored cross‑site scripting flaw in Kiteworks Core lets an unauthenticated attacker place malicious JavaScript that runs in the browser of an administrator who later views the crafted content. On execution the script gains the administrator’s session privileges, allowing the attacker to take full control of the system, create new administrative accounts, and access all protected data. This represents a full privilege escalation and compromise of the entire Kiteworks installation.
Affected Systems
The vulnerability affects the Kiteworks Core product. No version information is supplied in the advisory, so any deployment of Kiteworks Core that includes the affected content page is potentially impacted.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating a critical impact. The EPSS score is not available, but the lack of input validation and the ability to execute code in privileged sessions make exploitation feasible if an attacker can inject content before an administrator revisits the page. The advisory does not list the flaw in CISA’s KEV catalog, and no official workaround was provided, meaning mitigation must rely on patching or stricter controls.
OpenCVE Enrichment