CVE-2023-48469
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-48469 is a Cross-site Scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5.18 and below. This issue is DOM-based, meaning it exploits vulnerabilities in the handling of user input within the browser. An attacker can manipulate a URL to inject malicious JavaScript code into a webpage, which is then executed within the victim's browser if they visit the URL. Despite requiring a low-privileged attacker to lure the victim to the malicious URL, successful exploitation can lead to significant security risks. Adobe strongly recommends users update to the latest version of Adobe Experience Manager to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Experience Manager
- Adobe Experience Manager AEM Cloud Service
Affected Vendors
- Adobe