High severity8.1NVD Advisory· Published Oct 14, 2025· Updated Apr 28, 2026
CVE-2025-49552
CVE-2025-49552
Description
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- helpx.adobe.com/security/products/connect/apsb25-70.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.