CVE-2022-26327 MEDIUM

CVE-2022-26327: Stored cross-site scripting (XSS) has been discovered in OpenText™ Performance Center

Vendor Opentext
Product Performance Center
Weakness CWE-200 · Info exposure
Published August 21, 2024
Last update August 21, 2024

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/RE:M/U:Clear

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63.

Key dates

02Disclosure timeline

August 21, 2024 CVE published
August 21, 2024 Record updated