PT-2024-2409 · Adobe · Experience Manager

Published

2024-03-12

·

Updated

2024-12-03

·

CVE-2024-26056

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.19 and earlier
Description The issue exists due to inadequate protection of the web page structure in Adobe Experience Manager, allowing a remote attacker to execute arbitrary JavaScript code. This stored Cross-Site Scripting (XSS) vulnerability can be exploited by injecting malicious scripts into vulnerable form fields, which may result in the execution of malicious JavaScript in a victim's browser when they browse to the page containing the vulnerable field.
Recommendations For versions 6.5.19 and earlier, update to a version that includes the fix for this issue to prevent exploitation of the stored Cross-Site Scripting vulnerability. As a temporary workaround, consider restricting access to vulnerable form fields to minimize the risk of malicious script injection.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-02361
CVE-2024-26056

Affected Products

Experience Manager