Impact
Documentum Webtop versions before 16.7.1 contain a DOM‑based cross‑site scripting flaw that permits an attacker to inject and run arbitrary JavaScript when users access manipulated input or crafted URLs. The weakness, classified as CWE‑79, can lead to session hijacking, data theft, or other client‑side attacks.
Affected Systems
OpenText Documentum Webtop installations running any version earlier than 16.7.1.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. No EPSS value is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Nonetheless, the flaw can be triggered remotely via a web‑based attack, such as redirecting a user to a malicious link that exploits the DOM XSS, enabling the attacker to execute code inside the victim’s browser and potentially steal session data or perform unauthorized actions.
OpenCVE Enrichment