PT-2024-9656 · Adobe · Connect
Published
2024-11-27
·
Updated
2025-01-15
·
CVE-2024-54047
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Connect versions 11.4.7 and earlier
Adobe Connect version 12.6
Description
The issue is related to insufficient protection of the web page structure, allowing for a reflected Cross-Site Scripting (XSS) attack. If an attacker can convince a victim to visit a malicious URL referencing a vulnerable page, it may lead to the execution of malicious JavaScript content within the victim's browser context.
Recommendations
For Adobe Connect version 12.6, update to a version that includes a fix for this issue.
For Adobe Connect version 11.4.7 and earlier, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to vulnerable pages until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connect