First published: Fri Jun 12 2020(Updated: )
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | >=6.4<6.4.8.1 | |
Adobe Experience Manager | >=6.5<6.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9648 is classified as a critical vulnerability due to the potential for arbitrary JavaScript execution in users' browsers.
To mitigate CVE-2020-9648, update Adobe Experience Manager to version 6.5.6.0 or later.
CVE-2020-9648 affects Adobe Experience Manager versions 6.5 and earlier, specifically from version 6.4 to 6.5.5.0.
CVE-2020-9648 is a cross-site scripting (XSS) vulnerability, allowing for the execution of malicious scripts.
Successful exploitation of CVE-2020-9648 can lead to arbitrary JavaScript execution in a victim's web browser.