AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-45928

HIGH · CVSS 8.8 EPSS 1.74% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-45928
Severity
HIGH
CVSS
8.8
EPSS
1.74%

Original NVD Description

A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands.