Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8vg-fqfh-j78f

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

EPSS

Процентиль: 65%
0.00485
Низкий

Связанные уязвимости

CVSS3: 9
nvd
больше 5 лет назад

The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

CVSS3: 9
fstec
больше 5 лет назад

Уязвимость системы управления контентом и медиа-данными Adobe Experience Manager, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный JavaScript-код в браузере пользователя

EPSS

Процентиль: 65%
0.00485
Низкий