CVE-2016-7851: XSS
Published Nov 8, 2016
·Updated
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in cross-site scripting attacks.
Affected Software
1 affected component
Adobe Connect<=9.5.6
Remediation
Event History
Nov 8, 2016
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-7851?
The severity of CVE-2016-7851 is categorized as critical due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2016-7851?
To fix CVE-2016-7851, upgrade Adobe Connect to version 9.5.7 or later which contains the necessary patch.
3
What impact does CVE-2016-7851 have on users?
CVE-2016-7851 allows attackers to execute malicious scripts in the context of a user's session, compromising user data and session integrity.
4
Which versions of Adobe Connect are affected by CVE-2016-7851?
CVE-2016-7851 affects Adobe Connect versions 9.5.6 and earlier.
5
Is CVE-2016-7851 related to input validation?
Yes, CVE-2016-7851 is related to inadequate input validation in the events registration module of Adobe Connect.