Remote Code Execution Vulnerability in OpenText Content Suite Platform
CVE-2022-45928
8.8HIGH
Summary
A vulnerability in the OpenText Content Suite Platform enables remote OScript code execution via multiple endpoints that allow the injection of the 'htmlFile' parameter. This parameter is processed within the HTML output rendering pipeline, leading to evaluations and executions of OScript code contained in HTML files. As a result, an attacker could manipulate files on the filesystem, establish new network connections, or run operating system commands, escalating the risk of extensive damage to the platform and its underlying infrastructure.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved