Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-45928

Опубликовано: 18 янв. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opentext:opentext_extended_ecm:*:*:*:*:*:*:*:*
Версия от 16.2.2 (включая) до 22.3 (включая)

EPSS

Процентиль: 86%
0.02803
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-Other
CWE-94

Связанные уязвимости

CVSS3: 8.8
github
около 3 лет назад

A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands.

EPSS

Процентиль: 86%
0.02803
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-Other
CWE-94