CVE-2023-29304
CVSS 3.1 Score 5.4 of 10 (medium)
Attack Complexity low
Scope changed
Confidentiality low
Integrity low
Privileges Required low
Availability none
Details
Published Jun 15, 2023
Updated: Jun 22, 2023
CWE ID 79
Summary
CVE-2023-29304 is a reflected Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5.16.0 and below. This issue permits an attacker to inject malicious JavaScript code into a vulnerable page, which if visited by a victim, could result in the execution of the malicious script within the victim's browser. The attacker would need to convince a victim to click on a specially crafted URL to exploit this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Adobe Experience Manager
- Adobe Experience Manager AEM Cloud Service
Affected Vendors
- Adobe