Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-3010. PoCs published by Kamil Breński.
AI-analyzed exploit summary This exploit demonstrates two stored XSS vulnerabilities in OpenText Content Server 20.3. The first involves injecting malicious JavaScript via document version comments, while the second abuses the project banner URL field to execute arbitrary JavaScript when clicked.
Description
There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized.
Exploits (1)
This exploit demonstrates two stored XSS vulnerabilities in OpenText Content Server 20.3. The first involves injecting malicious JavaScript via document version comments, while the second abuses the project banner URL field to execute arbitrary JavaScript when clicked.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N