Remote Code Execution Vulnerability in OpenText Content Suite Platform
CVE-2022-45928

8.8HIGH

Key Information:

Vendor
Opentext
Vendor
CVE Published:
18 January 2023

Summary

A vulnerability in the OpenText Content Suite Platform enables remote OScript code execution via multiple endpoints that allow the injection of the 'htmlFile' parameter. This parameter is processed within the HTML output rendering pipeline, leading to evaluations and executions of OScript code contained in HTML files. As a result, an attacker could manipulate files on the filesystem, establish new network connections, or run operating system commands, escalating the risk of extensive damage to the platform and its underlying infrastructure.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.