PT-2023-14801 · Opentext · Opentext Content Suite Platform
Armin Stock
·
Published
2023-01-18
·
Updated
2025-04-04
·
CVE-2022-45928
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenText Content Suite Platform version 16.2.19.1803
Description
A remote OScript execution issue was discovered, allowing an attacker to execute OScript code by passing the
htmlFile parameter through multiple endpoints. The Content Server evaluates and executes OScript code in HTML files, enabling the attacker to manipulate files on the filesystem, create new network connections, or execute OS commands.Recommendations
For OpenText Content Suite Platform version 16.2.19.1803, consider restricting access to the
htmlFile parameter in the affected API endpoints until a patch is available. As a temporary workaround, disabling the execution of OScript code in HTML files could minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opentext Content Suite Platform