OpenText Content Management CE Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Discussions feature of OpenText Content Management CE versions 20.2 through 25.1, on both Windows and Linux. This vulnerability allows authenticated users to inject malicious code into the system, potentially leading to unauthorized actions against other users.

Impact

Exploitation of this vulnerability could enable an authenticated user to inject code that is executed in the context of the user, potentially leading to unauthorized actions or data exposure.

Remediation

A hotfix is available for OpenText Content Management (Extended ECM) versions CE 20.2 to 25.1. Users can upgrade to version 25.2 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.