CVE-2024-4187

July 31, 2024, 9:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

OpenText Filr

  • 24.1.1
  • 24.2

Source

security@opentext.com

Tags

CVE-2024-4187 details

Published : July 31, 2024, 9:15 p.m.
Last Modified : July 31, 2024, 9:15 p.m.

Description

Stored XSS vulnerability has been discovered in OpenTextâ„¢ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-356 Product UI does not Warn User of Unsafe Actions The product's user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.

References

URL Source
https://portal.microfocus.com/s/article/KM000032291 security@opentext.com
This website uses the NVD API, but is not approved or certified by it.