Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a malicious link.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Sep 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | AMS XSS - /libs/granite/ui/components/foundation/clientlibs/foundation/js/admin/propertiesactivator.js | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
Tue, 27 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe experience Manager |
|
CPEs | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* |
|
Vendors & Products |
Adobe
Adobe experience Manager |
Fri, 23 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 Aug 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a malicious link. | |
Title | AMS XSS - /libs/granite/ui/components/foundation/clientlibs/foundation/js/admin/propertiesactivator.js | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: adobe
Published: 2024-08-23T16:53:36.032Z
Updated: 2024-10-07T12:30:10.349Z
Reserved: 2024-07-22T17:16:40.945Z
Link: CVE-2024-41878
Vulnrichment
Updated: 2024-08-23T17:44:57.805Z
NVD
Status : Analyzed
Published: 2024-08-23T17:15:09.610
Modified: 2024-08-27T14:46:24.667
Link: CVE-2024-41878
Redhat
No data.