getFileExtension of the file src/main/java/com/openkm/util/FileUtils.java. This manipulation causes insecure temporary file.This vulnerability is tracked as CVE-2022-3969. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is recommended.
SOCIAL SHARE CARD GENERATOR