Impact
A stored Cross‑Site Scripting vulnerability allows an attacker to inject malicious JavaScript into vulnerable form fields within Adobe Connect. When a user visits a page containing the stored payload, the script executes in the victim’s browser context, potentially enabling the attacker to hijack the user’s session or gain elevated control over the account. The flaw also changes the affected system’s security scope, indicating broader vulnerability reach.
Affected Systems
Adobe Connect for web clients and the Adobe Connect Android Mobile App are impacted. The vulnerability affects all installations that allow users to create or edit form fields stored by the application, regardless of operating system.
Risk and Exploitability
The CVSS score of 9.3 highlights a critical impact. Because the vulnerability can elevate an attacker’s privileges within the application, it demands immediate attention. While the EPSS score is not available, the high CVSS indicates that an attacker with the ability to inject content can cause substantial damage. The vulnerability is not catalogued in KEV, but a lack of public exploitation does not lessen the risk posed by a high‑score stored XSS flaw. The likely attack vector is through manipulation of form fields that persist user input across sessions, and the vulnerability is inferred to be exploitable by those with write access to those fields.
OpenCVE Enrichment