Medium severity6.5NVD Advisory· Published Feb 19, 2026· Updated Jun 17, 2026
CVE-2025-13671
CVE-2025-13671
Description
Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously.
This issue affects Web Site Management Server: 16.7.0, 16.7.1.
Affected products
4cpe:2.3:a:opentext:web_site_management_server:16.7.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:opentext:web_site_management_server:16.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:opentext:web_site_management_server:16.7.1:*:*:*:*:*:*:*
- (no CPE)range: 16.7.0, 16.7.1
- (no CPE)range: 16.7.0
Patches
Vulnerability mechanics
References
2- github.com/MarioTesoro/vulnerability-research/blob/main/CVE-2025-13671/README.mdnvdExploitThird Party Advisory
- support.opentext.com/csm/ennvdVendor Advisory
News mentions
0No linked articles in our index yet.