Stored XSS Vulnerability in Adobe Connect Affects Multiple Versions
CVE-2025-30315

6.1MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 May 2025

What is CVE-2025-30315?

Adobe Connect versions 12.8 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts into form fields. When users access affected pages, harmful JavaScript could execute in their browsers, leading to potential data theft and session hijacking. This vulnerability emphasizes the importance of secure coding practices and user input validation to mitigate such risks.

Affected Version(s)

Adobe Connect 0 <= 12.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30315 : Stored XSS Vulnerability in Adobe Connect Affects Multiple Versions