CVE-2024-53962

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 5, 2025
Updated: Feb 11, 2025
CWE ID 79

Summary

CVE-2024-53962 is a stored Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5.21 and prior. This issue allows a low privileged attacker to inject malicious scripts into vulnerable form fields. By exploiting this flaw, an adversary can execute malicious JavaScript in a victim's browser when they visit the affected webpage, potentially leading to data theft or other malicious activities. This vulnerability poses a significant risk to organizations using these Adobe Experience Manager versions and should be addressed promptly by applying the available patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Experience Manager

Affected Vendors

  • Adobe