Unrated severityNVD Advisory· Published Mar 18, 2024· Updated Oct 7, 2024
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2024-26064
Description
Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into a webpage. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser. Exploitation of this issue requires user interaction.
Affected products
2<=6.5.19+ 1 more
- (no CPE)range: <=6.5.19
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/experience-manager/apsb24-05.htmlmitrevendor-advisory
News mentions
0No linked articles in our index yet.