First published: Tue Feb 27 2018(Updated: )
Adobe Experience Manager versions 6.3, 6.2, and 6.1 are vulnerable to cross-site scripting via a bypass of the Sling XSSAPI#getValidHref function.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | =6.1.0 | |
Adobe Experience Manager | =6.2.0 | |
Adobe Experience Manager | =6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4876 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To mitigate CVE-2018-4876, update Adobe Experience Manager to version 6.3.1, 6.2.1, or 6.1.1 or later.
CVE-2018-4876 can allow attackers to perform cross-site scripting attacks, potentially leading to user data theft or session hijacking.
CVE-2018-4876 affects Adobe Experience Manager versions 6.1, 6.2, and 6.3.
Yes, user data may be at risk if an attacker successfully exploits CVE-2018-4876 through cross-site scripting.