CVE-2018-4876: XSS
Published Feb 27, 2018
·Updated
Adobe Experience Manager versions 6.3, 6.2, and 6.1 are vulnerable to cross-site scripting via a bypass of the Sling XSSAPI#getValidHref function.
Affected Software
3 affected components
Adobe Experience Manager=6.1.0
Adobe Experience Manager=6.2.0
Adobe Experience Manager=6.3.0
Remediation
Event History
Feb 27, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-4876?
CVE-2018-4876 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2018-4876?
To mitigate CVE-2018-4876, update Adobe Experience Manager to version 6.3.1, 6.2.1, or 6.1.1 or later.
3
What types of attacks can CVE-2018-4876 allow?
CVE-2018-4876 can allow attackers to perform cross-site scripting attacks, potentially leading to user data theft or session hijacking.
4
Which Adobe Experience Manager versions are affected by CVE-2018-4876?
CVE-2018-4876 affects Adobe Experience Manager versions 6.1, 6.2, and 6.3.
5
Is user data at risk due to CVE-2018-4876?
Yes, user data may be at risk if an attacker successfully exploits CVE-2018-4876 through cross-site scripting.