CVE-2022-45928: Code Injection
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45928?
CVE-2022-45928 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-45928?
To remediate CVE-2022-45928, apply the latest patches provided by OpenText that specifically address this vulnerability.
What software versions are affected by CVE-2022-45928?
CVE-2022-45928 affects OpenText Content Suite Platform versions between 16.2.2 and 22.3.
How does CVE-2022-45928 allow for remote code execution?
CVE-2022-45928 allows remote code execution by permitting unauthorized users to pass manipulated parameters to the OScript execution environment.
Are there known exploits for CVE-2022-45928?
Yes, there are known exploits that take advantage of the remote OScript execution capability in CVE-2022-45928.