OpenText Filr
cpe:2.3:a:opentext:filr:*:*:*:*:*:*:*
- <= 25.1.2
A missing authorization vulnerability in OpenText Filr, affecting all versions through 25.1.2, allows authentication bypass. This vulnerability could enable unauthenticated users to obtain an XSRF token and perform remote procedure calls (RPC) using carefully crafted programs.
Exploitation of this vulnerability could lead to unauthorized access and actions being performed on behalf of an authenticated user, by allowing unauthenticated users to obtain XSRF tokens and execute RPCs with them.
Users can update to the latest version of Filr (25.4.1), apply the Filr 25.1.3 patch release, or contact OpenText technical support for 24.4 and 23.4 PTFs.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.