CVE-2018-12806: XSS
Published Aug 29, 2018
·Updated
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
2 affected components
Adobe Experience Manager>=6.1.2.1<=6.1.2.16
Adobe Experience Manager>=6.2.1.1<=6.2.1.15
Remediation
Event History
Aug 29, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-12806?
CVE-2018-12806 is classified as a medium severity reflected cross-site scripting vulnerability.
2
How do I fix CVE-2018-12806?
To fix CVE-2018-12806, update Adobe Experience Manager to the latest version that is not affected by this vulnerability.
3
What versions of Adobe Experience Manager are affected by CVE-2018-12806?
Affected versions include Adobe Experience Manager 6.4, 6.3, 6.2, 6.1, and 6.0.
4
What are the potential impacts of CVE-2018-12806?
Successful exploitation of CVE-2018-12806 could lead to the disclosure of sensitive information from the application.
5
Is there a workaround for CVE-2018-12806?
There are no known workarounds for CVE-2018-12806; updating the software is the recommended approach.