Impact
Adobe Connect is vulnerable to stored cross‑site scripting, allowing an attacker to embed malicious JavaScript into protected form fields that are later rendered to other users. When a victim browses the affected page, the injected script runs in the context of that page, potentially stealing authentication cookies or executing additional payloads. The vulnerability is classified as scope changing, meaning exploitation may affect other users or system resources beyond the initially targeted user.
Affected Systems
Affected products include Adobe Connect for desktop and Adobe Connect Android Mobile App. No specific version numbers are listed in the advisory, so all current releases are presumed vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score is currently unavailable, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector employs users who can submit or edit form data; after injection, any other user who views the page would be exposed to the malicious script. Because the vulnerability changes scope, an attacker may leverage this to spread further across the platform.
OpenCVE Enrichment