CVE-2020-24442: Reflected Cross-Site Scripting (XSS) in Adobe Connect
Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24442?
CVE-2020-24442 is a reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect version 11.0 (and earlier).
How does CVE-2020-24442 affect Adobe Connect?
CVE-2020-24442 allows an attacker to execute malicious JavaScript within a victim's browser if the victim visits a URL referencing a vulnerable page.
What is the severity of CVE-2020-24442?
CVE-2020-24442 has a severity rating of 6.1 (medium).
How can I check if my Adobe Connect version 11.0 is vulnerable to CVE-2020-24442?
To check if your Adobe Connect version 11.0 is vulnerable to CVE-2020-24442, you can refer to the vulnerability details and advisory provided by Adobe.
How do I mitigate the CVE-2020-24442 vulnerability in Adobe Connect?
To mitigate the CVE-2020-24442 vulnerability in Adobe Connect, it is recommended to update to a patched version of the software when it becomes available.