PT-2024-9521 · Adobe · Connect

Published

2024-12-10

·

Updated

2025-01-15

·

CVE-2024-54032

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Adobe Connect versions 11.4.7 and earlier Adobe Connect version 12.6
Description The issue is related to the lack of protection of the web page structure in Adobe Connect, allowing a remote attacker to elevate privileges and execute arbitrary code. This is a stored Cross-Site Scripting (XSS) vulnerability that can be abused by an attacker to inject malicious scripts into vulnerable form fields. When a victim browses to the page containing the vulnerable field, malicious JavaScript may be executed in their browser. A successful attack can lead to session takeover, significantly increasing the impact on confidentiality and integrity.
Recommendations For Adobe Connect versions 11.4.7 and earlier, update to a version that includes the fix for this issue. For Adobe Connect version 12.6, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to vulnerable form fields until a patch is available. Avoid using vulnerable form fields in Adobe Connect until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-11221
CVE-2024-54032

Affected Products

Connect