First published: Fri Jul 14 2017(Updated: )
Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability. Successful exploitation could lead to a reflected cross-site scripting attack.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Connect Enterprise Server | <=9.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3102 has been classified as a medium severity vulnerability due to its potential to enable reflected cross-site scripting attacks.
To mitigate CVE-2017-3102, users should update Adobe Connect to version 9.6.2 or later as patches have been released.
Reflected cross-site scripting in CVE-2017-3102 allows attackers to inject malicious scripts into web pages viewed by users resulting in unauthorized actions.
CVE-2017-3102 specifically affects Adobe Connect versions 9.6.1 and earlier.
Exploitation of CVE-2017-3102 could allow attackers to steal session cookies or redirect users to malicious websites.