First published: Fri Jun 12 2020(Updated: )
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | >=6.4<6.4.8.1 | |
Adobe Experience Manager | >=6.5<6.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9644 has a high severity rating due to the potential for arbitrary JavaScript execution in the browser.
To fix CVE-2020-9644, upgrade Adobe Experience Manager to version 6.5.6.0 or later.
Adobe Experience Manager versions 6.5 and earlier, specifically up to 6.5.5.0, are affected by CVE-2020-9644.
CVE-2020-9644 is classified as a stored cross-site scripting (XSS) vulnerability.
Exploitation of CVE-2020-9644 could allow attackers to execute malicious JavaScript in the context of users' browsers.