Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

CVE-2024-49524
5.4MEDIUM

Key Information

Vendor
Adobe
Status
Adobe Experience Manager
Vendor
CVE Published:
7 November 2024

Summary

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to access a manipulated URL or provide specific input to trigger the vulnerability.

Affected Version(s)

Adobe Experience Manager <= 6.5.20

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database
.