Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fq5r-22jj-7j7q

Опубликовано: 05 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.4

Описание

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. 

A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system.

This issue affects Content Management (Extended ECM): from 10.0 through 24.4 

with WebReports module installed and enabled.

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. 

A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system.

This issue affects Content Management (Extended ECM): from 10.0 through 24.4 

with WebReports module installed and enabled.

EPSS

Процентиль: 30%
0.00111
Низкий

5.4 Medium

CVSS4

Дефекты

CWE-1287

Связанные уязвимости

nvd
около 1 года назад

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection.  A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system. This issue affects Content Management (Extended ECM): from 10.0 through 24.4  with WebReports module installed and enabled.

EPSS

Процентиль: 30%
0.00111
Низкий

5.4 Medium

CVSS4

Дефекты

CWE-1287