DOM-based Cross-Site Scripting Vulnerability in Adobe Connect
CVE-2025-49553

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 October 2025

What is CVE-2025-49553?

Adobe Connect versions 12.9 and prior have a DOM-based Cross-Site Scripting vulnerability, allowing attackers to execute harmful scripts within a victim's browser. Exploitation necessitates user interaction, as victims must visit a specifically crafted web page. This exploitation may lead to session takeover, compromising user data and system integrity.

Affected Version(s)

Adobe Connect 0 <= 12.9

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49553 : DOM-based Cross-Site Scripting Vulnerability in Adobe Connect