- Description
- Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
- Source
- psirt@adobe.com
- NVD status
- Analyzed
- Products
- connect, connect_desktop_application
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- psirt@adobe.com
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:*",
"matchCriteriaId": "4A1D88E9-612C-49B1-8521-F2258D4D74CA",
"versionEndExcluding": "12.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:macos:*:*",
"matchCriteriaId": "185BF6E9-82FC-45E0-A64E-03FB923F34AD",
"versionEndIncluding": "2025.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "783AAAA9-E68B-43E3-86A3-5227E27392A5",
"versionEndExcluding": "2025.9.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]