CVE-2024-53970

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 19, 2025
CWE ID 79

Summary

CVE-2024-53970 is a stored Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5.21 and prior. This issue allows a low privileged attacker to inject malicious scripts into vulnerable form fields. By exploiting this flaw, an adversary can execute harmful JavaScript in a victim's browser when they visit the affected page. This could potentially lead to data theft, unauthorized access, or other malicious activities. Users are advised to upgrade to a patched version of Adobe Experience Manager as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share