CVE 5.9 MEDIUM

Cross Site request forgery vulnerability discovered in OpenText WSM Management Server._CVE-2025-13671

5.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:L/SI:N/SA:N/S:P/AU:N/R:U/V:D/RE:H/U:Red

Description

Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously.

This issue affects Web Site Management Server: 16.7.0, 16.7.1.

Basic Information

ID CVE-2025-13671
Source OpenText
Published Feb 19, 2026 at 22:36

Affected Product

Vendor OpenText™
Product Web Site Management Server
Version 16.7.0
Affected Versions OpenText™ Web Site Management Server 16.7.0
OpenText™ Web Site Management Server 16.7.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.