CVE-2015-6530: Opentext Secure MFT 2013

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013 before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to userdashboard.jsp.

Affected products

  • Opentext Secure MFT 2013: up to and including r3
  • Opentext Secure MFT 2014: up to and including r2

Published 2015-08-20. Last modified 2026-06-17.