Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2025-04-23T19:27:30.869Z

Reserved: 2021-09-08T00:00:00.000Z

Link: CVE-2021-40711

cve-icon Vulnrichment

Updated: 2024-08-04T02:51:06.982Z

cve-icon NVD

Status : Modified

Published: 2021-09-27T16:15:10.587

Modified: 2024-11-21T06:24:36.763

Link: CVE-2021-40711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.