Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23344 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. |
Thu, 12 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. |
Mon, 02 Dec 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:* cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* |
Mon, 07 Oct 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Admin Account cookie exfiltration using Stored XSS injected via Blueprints title and triggered at /siteadmin while adding "New Site" | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-12-12T17:04:53.677Z
Reserved: 2024-02-14T17:37:23.389Z
Link: CVE-2024-26050
Updated: 2024-08-01T23:59:32.313Z
Status : Analyzed
Published: 2024-03-18T18:15:13.263
Modified: 2024-12-12T21:13:12.177
Link: CVE-2024-26050
No data.
OpenCVE Enrichment
No data.
EUVD