CVE-2020-24445: Cross-site Scripting Vulnerability in Commenting Function of Adobe Experience Manager (AEM)
AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24445?
CVE-2020-24445 has a high severity rating due to its potential for stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2020-24445?
To remediate CVE-2020-24445, upgrade to a version of Adobe Experience Manager that is above 6.5.6.0 or apply the necessary security updates provided by Adobe.
Which Adobe Experience Manager versions are affected by CVE-2020-24445?
CVE-2020-24445 affects Adobe Experience Manager versions up to and including 6.5.6.0 and the Adobe Experience Manager Cloud Service.
What type of vulnerability is CVE-2020-24445?
CVE-2020-24445 is identified as a stored Cross-Site Scripting (XSS) vulnerability that may allow the injection of malicious scripts.
Can CVE-2020-24445 lead to data compromise?
Yes, exploitation of CVE-2020-24445 could lead to unauthorized access, session hijacking, and data compromise.