Show filters
286 Total Results
Displaying 91-100 of 286
Sort by:
Attacker Value
Unknown
CVE-2022-45928
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands.
0
Attacker Value
Unknown
CVE-2022-45926
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.
0
Attacker Value
Unknown
CVE-2022-45925
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.
0
Attacker Value
Unknown
CVE-2022-45924
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user to delete arbitrary files on the server's local filesystem.
0
Attacker Value
Unknown
CVE-2022-45922
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password.
0
Attacker Value
Unknown
CVE-2022-4099
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection
0
Attacker Value
Unknown
CVE-2021-38561
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
0
Attacker Value
Unknown
CVE-2020-36624
Disclosure Date: December 22, 2022 (last updated February 24, 2025)
A vulnerability was found in ahorner text-helpers up to 1.0.x. It has been declared as critical. This vulnerability affects unknown code of the file lib/text_helpers/translation.rb. The manipulation of the argument link leads to use of web link to untrusted target with window.opener access. The attack can be initiated remotely. Upgrading to version 1.1.0 is able to address this issue. The name of the patch is 184b60ded0e43c985788582aca2d1e746f9405a3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216520.
0
Attacker Value
Unknown
CVE-2022-32149
Disclosure Date: October 14, 2022 (last updated February 24, 2025)
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
0
Attacker Value
Unknown
CVE-2022-3036
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The Gettext override translations WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0