Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-4187

July 31, 2024, 9:15 p.m.

Product(s) Impacted

OpenText Filr

  • 24.1.1
  • 24.2

Description

Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

Weaknesses

CWE-356
Product UI does not Warn User of Unsafe Actions

The product's user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.

CWE ID: 356

Date

Published: July 31, 2024, 9:15 p.m.

Last Modified: July 31, 2024, 9:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security@opentext.com

References

https://portal.microfocus.com/ security@opentext.com