CVE-2025-9208: Stored-XSS vulnerability discovered in OpenText WSM Management Server.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data.
This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9208?
CVE-2025-9208 is classified as a high severity vulnerability due to its potential to allow stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-9208?
To fix CVE-2025-9208, it is recommended to upgrade OpenText Web Site Management Server to version 16.8.3 or higher.
How does CVE-2025-9208 affect OpenText Web Site Management Server?
CVE-2025-9208 affects OpenText Web Site Management Server by allowing attackers to execute malicious scripts on the client side through improper neutralization of input.
Who is affected by CVE-2025-9208?
Any users of OpenText Web Site Management Server versions 16.7.0 to 16.8.2 are affected by CVE-2025-9208.
What is the nature of the vulnerability in CVE-2025-9208?
The nature of the vulnerability in CVE-2025-9208 is an improper neutralization of input during web page generation, specifically allowing stored XSS.