CVE-2025-13672 PUBLISHED

Reflected Cross-Site Scripting discovered in OpenText WSM Management Server.

Assigner: OpenText
Reserved: 25.11.2025 Published: 19.02.2026 Updated: 19.02.2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side.

This issue affects Web Site Management Server: 16.7.0, 16.7.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/S:P/AU:N/R:U/V:D/RE:H/U:Red
CVSS Score: 7

Product Status

Vendor OpenText™
Product Web Site Management Server
Versions Default: unaffected
  • Version 16.7.0 is affected
  • Version 16.7.1 is affected

Solutions

https://support.opentext.com/csm/en?id=ot_kb_unauthenticated&sysparm_article=KB0854847

Credits

  • Mario Tesoro finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS