First published: Thu Nov 12 2020(Updated: )
Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Connect | <=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24443 is a reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect version 11.0 and earlier.
CVE-2020-24443 allows an attacker to execute malicious JavaScript content within the context of a victim's browser by convincing them to visit a URL referencing a vulnerable page.
The severity of CVE-2020-24443 is medium, with a CVSS score of 6.1.
To fix CVE-2020-24443 in Adobe Connect, it is recommended to update to the latest version, which has the vulnerability patched.
More information about CVE-2020-24443 can be found at the following link: [https://helpx.adobe.com/security/products/connect/apsb20-69.html](https://helpx.adobe.com/security/products/connect/apsb20-69.html)