Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w7fv-jgcc-fw22

Опубликовано: 14 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

EPSS

Процентиль: 90%
0.0528
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 8.1
fstec
около 4 лет назад

Уязвимость системы управления контентом и медиа-данными Adobe Experience Manager, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.0528
Низкий

Дефекты

CWE-79