CVE-2018-5005: XSS
Published Sep 6, 2018
·Updated
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Affected Software
3 affected components
Adobe Experience Manager>=6.3.2.1<=6.3.2.2
Adobe Experience Manager=6.4
Adobe Experience Manager>=6.2.1.1<=6.2.1.14
Remediation
Event History
Sep 6, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-5005?
CVE-2018-5005 is classified as a moderate severity Cross-site Scripting vulnerability affecting Adobe Experience Manager.
2
How do I fix CVE-2018-5005?
To remediate CVE-2018-5005, upgrade Adobe Experience Manager to the latest version available.
3
Which versions are affected by CVE-2018-5005?
CVE-2018-5005 affects Adobe Experience Manager versions 6.0 through 6.4, specifically certain subversions.
4
What could an attacker do by exploiting CVE-2018-5005?
Successful exploitation of CVE-2018-5005 may allow an attacker to disclose sensitive information.
5
Is CVE-2018-5005 a client-side or server-side vulnerability?
CVE-2018-5005 is primarily a client-side vulnerability as it involves Cross-site Scripting.