- Description
- Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
- Source
- psirt@adobe.com
- NVD status
- Analyzed
- Products
- experience_manager
CVSS 3.1
- Type
- Secondary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- psirt@adobe.com
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*",
"matchCriteriaId": "C8849F58-C7F7-4E39-A3F0-6305BAE9D523",
"versionEndIncluding": "6.5.25.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*",
"matchCriteriaId": "A16BC589-7E8B-4FB8-B6D2-3CC5549D7A06",
"versionEndIncluding": "2020.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*",
"matchCriteriaId": "852C2582-859F-40DB-96CF-E1274CEECC1F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*",
"matchCriteriaId": "00DDCBAD-1FEF-487F-97BB-481DC02F493A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*",
"matchCriteriaId": "28842AFC-C6CB-4F63-82B6-7B42E291D4E0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]