PT-2025-17443 · Opentext · Opentext Content Management

·

CVE-2024-12863

·

Published

2025-04-21

·

Updated

2025-04-21

CVSS v4.0

5.6

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenText Content Management CE versions 20.2 through 25.1
Description The issue allows authenticated malicious users to inject code into the system through a Stored XSS in Discussions. This affects OpenText Content Management CE on both Windows and Linux platforms.
Recommendations For versions 20.2 through 25.1, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the Discussions feature to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12863

Affected Products

Opentext Content Management