CVE-2023-29304

CVSS 3.1 Score 5.4 of 10 (medium)

Attack Complexity low
Scope changed
Confidentiality low
Integrity low
Privileges Required low
Availability none

Details

Published Jun 15, 2023
Updated: Jun 22, 2023
CWE ID 79

Summary

CVE-2023-29304 is a reflected Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5.16.0 and below. This issue permits an attacker to inject malicious JavaScript code into a vulnerable page, which if visited by a victim, could result in the execution of the malicious script within the victim's browser. The attacker would need to convince a victim to click on a specially crafted URL to exploit this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Experience Manager
  • Adobe Experience Manager AEM Cloud Service

Affected Vendors

  • Adobe