PT-2025-17443 · Opentext · Opentext Content Management

Hussein Bahmad

·

Published

2025-04-21

·

Updated

2025-04-21

·

CVE-2024-12863

CVSS v4.0

5.6

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenText Content Management CE versions 20.2 through 25.1
Description The issue allows authenticated malicious users to inject code into the system through a Stored XSS in Discussions. This affects OpenText Content Management CE on both Windows and Linux platforms.
Recommendations For versions 20.2 through 25.1, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the Discussions feature to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-12863

Affected Products

Opentext Content Management