Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-43720


Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, an attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link.


Published

2024-12-10T22:15:07.160

Last Modified

2024-12-17T15:23:30.417

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe experience_manager < 6.5.22.0 Yes
Application adobe experience_manager < 2024.11.0 Yes

References