Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8125

Опубликовано: 04 фев. 2025
Источник: nvd
EPSS Низкий

Описание

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. 

A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system.

This issue affects Content Management (Extended ECM): from 10.0 through 24.4 

with WebReports module installed and enabled.

EPSS

Процентиль: 30%
0.00111
Низкий

Дефекты

CWE-1287

Связанные уязвимости

github
около 1 года назад

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection.  A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system. This issue affects Content Management (Extended ECM): from 10.0 through 24.4  with WebReports module installed and enabled.

EPSS

Процентиль: 30%
0.00111
Низкий

Дефекты

CWE-1287