First published: Tue Feb 27 2018(Updated: )
Adobe Experience Manager versions 6.1 and 6.0 are vulnerable to a reflected cross-site scripting vulnerability related to the handling of malicious content embedded in image files uploaded to the DAM.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | =6.0.0 | |
Adobe Experience Manager | =6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4875 is classified as a medium severity vulnerability.
To fix CVE-2018-4875, upgrade to Adobe Experience Manager versions 6.1.1 or later.
CVE-2018-4875 enables reflected cross-site scripting attacks through malicious image file uploads.
CVE-2018-4875 affects Adobe Experience Manager versions 6.0 and 6.1.
Exploiting CVE-2018-4875 could lead to unauthorized actions on behalf of users, data theft, or session hijacking.