CVE-2024-12863
Stored XSS in Discussions functionality
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.6EPSS 0.3%KEV nãoPoC —Patch —
Lifecycle
Apr 21, 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
OpenText · OpenText Content ManagementWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →