PT-2023-14801 · Opentext · Opentext Content Suite Platform

Armin Stock

·

Publicado

2023-01-18

·

Atualizado

2025-04-04

·

CVE-2022-45928

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenText Content Suite Platform version 16.2.19.1803
Description A remote OScript execution issue was discovered, allowing an attacker to execute OScript code by passing the htmlFile parameter through multiple endpoints. The Content Server evaluates and executes OScript code in HTML files, enabling the attacker to manipulate files on the filesystem, create new network connections, or execute OS commands.
Recommendations For OpenText Content Suite Platform version 16.2.19.1803, consider restricting access to the htmlFile parameter in the affected API endpoints until a patch is available. As a temporary workaround, disabling the execution of OScript code in HTML files could minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-45928

Produtos afetados

Opentext Content Suite Platform