CVE-2025-13671: Cross Site request forgery vulnerability discovered in OpenText WSM Management Server.
Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously.
This issue affects Web Site Management Server: 16.7.0, 16.7.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13671?
CVE-2025-13671 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-13671?
To fix CVE-2025-13671, update the OpenText Web Site Management Server to version 16.7.2 or later.
Who is affected by CVE-2025-13671?
CVE-2025-13671 affects users of OpenText Web Site Management Server versions 16.7.0 to 16.7.1.
What type of vulnerability is CVE-2025-13671?
CVE-2025-13671 is a Cross-Site Request Forgery (CSRF) vulnerability.
What could an attacker achieve with CVE-2025-13671?
An attacker could exploit CVE-2025-13671 to perform unauthorized actions on behalf of an authenticated user.