PT-2022-19260 · Adobe · Acs Commons

Published

2022-04-21

·

Updated

2022-05-03

·

CVE-2022-28820

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ACS Commons versions 5.1.x and earlier
Description The issue is a Reflected Cross-site Scripting (XSS) vulnerability in the "/apps/acs-commons/content/page-compare.html" endpoint via the a and b GET parameters. User input submitted via these parameters is not validated or sanitized. An attacker must provide a link to someone with access to AEM Author, and could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable form fields and execute it within the context of the victim's browser. The exploitation of this issue requires user interaction in order to be successful.
Recommendations For ACS Commons versions 5.1.x and earlier, update to version 5.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the "/apps/acs-commons/content/page-compare.html" endpoint and avoiding the use of the a and b GET parameters until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28820
GHSA-W5M2-299G-RFF5

Affected Products

Acs Commons