PT-2024-9521 · Adobe · Connect
Published
2024-12-10
·
Updated
2025-01-15
·
CVE-2024-54032
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Connect versions 11.4.7 and earlier
Adobe Connect version 12.6
Description
The issue is related to the lack of protection of the web page structure in Adobe Connect, allowing a remote attacker to elevate privileges and execute arbitrary code. This is a stored Cross-Site Scripting (XSS) vulnerability that can be abused by an attacker to inject malicious scripts into vulnerable form fields. When a victim browses to the page containing the vulnerable field, malicious JavaScript may be executed in their browser. A successful attack can lead to session takeover, significantly increasing the impact on confidentiality and integrity.
Recommendations
For Adobe Connect versions 11.4.7 and earlier, update to a version that includes the fix for this issue.
For Adobe Connect version 12.6, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to vulnerable form fields until a patch is available.
Avoid using vulnerable form fields in Adobe Connect until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connect