PT-2024-9660 · Adobe · Connect

Published

2024-11-27

·

Updated

2025-01-15

·

CVE-2024-54051

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Adobe Connect versions 12.6, 11.4.7 and earlier
Description The issue is related to a URL redirection vulnerability to an untrusted site, also known as an "Open Redirect". This could allow a remote attacker to bypass existing security restrictions by redirecting users to malicious websites. Exploitation of this issue requires user interaction.
Recommendations For Adobe Connect versions 12.6, 11.4.7 and earlier, update to a version that fixes the URL redirection vulnerability to prevent attackers from redirecting users to malicious websites. As a temporary workaround, consider restricting access to untrusted sites to minimize the risk of exploitation. Avoid clicking on suspicious links from Adobe Connect to prevent potential redirection to malicious websites. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2024-11372
CVE-2024-54051

Affected Products

Connect