Stored XSS Vulnerability in Adobe Connect Affects User Security
CVE-2025-30314

6.1MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 May 2025

What is CVE-2025-30314?

Adobe Connect versions 12.8 and earlier are susceptible to a stored Cross-Site Scripting vulnerability. This allows attackers to inject malicious scripts into form fields, which may result in the execution of harmful JavaScript within the browsers of users accessing the affected pages. Exploiters could potentially manipulate user sessions, steal sensitive data, or perform actions on behalf of users without their consent, posing significant risks to user privacy and security.

Affected Version(s)

Adobe Connect 0 <= 12.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30314 : Stored XSS Vulnerability in Adobe Connect Affects User Security