CVE Vulnerabilities

CVE-2024-4187

Product UI does not Warn User of Unsafe Actions

Published: Jul 31, 2024 | Modified: Aug 15, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Stored XSS vulnerability has been discovered in OpenTextâ„¢ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

Weakness

The product’s user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.

Affected Software

NameVendorStart VersionEnd Version
FilrOpentext24.1.1 (including)24.1.1 (including)
FilrOpentext24.2 (including)24.2 (including)

References