logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-45922

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-45922

Description:
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password.
Last updated date:
01/26/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/26/2023
Reference url to background

http://packetstormsecurity.com/files/170615/OpenText-Extended-ECM-22.3-File-Deletion-LFI-Privilege-Escsalation.html

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/26/2023
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy