CVE-2023-48490
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-48490 is a Cross-site Scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5.18 and earlier. This issue is DOM-based, meaning it can be triggered by manipulating URLs on vulnerable pages. If a user visits such a URL, malicious JavaScript code can be executed within their browser, potentially stealing sensitive information or taking control of their session. Attackers with low privileges can exploit this vulnerability to conduct attacks. Users are advised to update their Adobe Experience Manager instances to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Experience Manager
- Adobe Experience Manager AEM Cloud Service
Affected Vendors
- Adobe