PT-2023-1984 · Adobe · Experience Manager

Publicado

2023-03-14

·

Atualizado

2023-03-31

·

CVE-2023-22258

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.15.0 and earlier
Description The issue is related to a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction. The vulnerability allows a remote attacker to bypass security restrictions.
Recommendations For versions 6.5.15.0 and earlier, update to a version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of redirection to malicious sites. Avoid using links from untrusted sources within the application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01607
CVE-2023-22258

Produtos afetados

Experience Manager