Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c9x-whr5-j4x3

Опубликовано: 18 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.

EPSS

Процентиль: 85%
0.02682
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.

EPSS

Процентиль: 85%
0.02682
Низкий

7.5 High

CVSS3

Дефекты

CWE-200