CVE-2025-13672: Reflected Cross-Site Scripting discovered in OpenText WSM Management Server.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side.
This issue affects Web Site Management Server: 16.7.0, 16.7.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13672?
CVE-2025-13672 is classified as a moderate severity vulnerability due to its potential to allow reflected cross-site scripting attacks.
How do I fix CVE-2025-13672?
To fix CVE-2025-13672, update your OpenText Web Site Management Server to a version later than 16.7.1.
Which versions of OpenText Web Site Management Server are affected by CVE-2025-13672?
CVE-2025-13672 affects OpenText Web Site Management Server versions from 16.7.0 to 16.7.1.
What type of vulnerability is CVE-2025-13672?
CVE-2025-13672 is a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2025-13672 be exploited by untrusted users?
Yes, CVE-2025-13672 can be exploited by untrusted users through specially crafted input that triggers the reflected XSS.