CVE-2016-0955: XSS
Published Feb 10, 2016
·Updated
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.
Affected Software
4 affected components
Adobe Experience Manager=6.1.0
Apple iOS and macOS
Linux Linux kernel
Microsoft Windows
Remediation
Event History
Feb 10, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0955?
CVE-2016-0955 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2016-0955?
To fix CVE-2016-0955, upgrade to a patched version of Adobe Experience Manager beyond 6.1.0.
3
Who is affected by CVE-2016-0955?
Remote authenticated users of Adobe Experience Manager version 6.1.0 are affected by CVE-2016-0955.
4
What type of vulnerability is CVE-2016-0955?
CVE-2016-0955 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2016-0955?
Attackers can inject arbitrary web scripts or HTML through the folder title field in the Deletion popup dialog.