PT-2020-5066 · Adobe · Experience Manager

Published

2020-09-08

·

Updated

2020-09-16

·

CVE-2020-9742

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.5.0 and earlier Adobe Experience Manager versions 6.4.8.1 and earlier Adobe Experience Manager versions 6.3.3.8 and earlier
Description The issue is related to insufficient protection of the web page structure, allowing a remote attacker to execute arbitrary JavaScript code in a user's browser using a specially crafted web page. It is a stored XSS vulnerability that enables users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature, which can be executed when a victim opens the page containing the vulnerable field.
Recommendations For Adobe Experience Manager versions 6.5.5.0 and earlier, update to a version that includes the fix for this issue. For Adobe Experience Manager versions 6.4.8.1 and earlier, update to a version that includes the fix for this issue. For Adobe Experience Manager versions 6.3.3.8 and earlier, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Inbox calendar feature to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05655
CVE-2020-9742

Affected Products

Experience Manager