CVE-2023-48477
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-48477 is a Cross-site Scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5.18 and below. This DOM-based XSS issue allows a low-privileged attacker to inject malicious JavaScript code into a webpage, which can be executed in the victim's browser when they visit a specially crafted URL. Successful exploitation of this vulnerability could lead to data theft, session hijacking, or unauthorized actions on behalf of the victim. Users are strongly advised to update their Adobe Experience Manager instances to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Experience Manager
- Adobe Experience Manager AEM Cloud Service
Affected Vendors
- Adobe