First published: Thu Sep 10 2020(Updated: )
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | >=6.4.0.0<=6.4.8.1 | |
Adobe Experience Manager | >=6.5.0.0<=6.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9734 is classified as a stored Cross-Site Scripting (XSS) vulnerability which poses a significant security risk to affected versions.
To mitigate CVE-2020-9734, update Adobe Experience Manager to version 6.5.5.1 or later, or 6.4.8.2 or later.
Users with 'Author' privileges on affected versions of Adobe Experience Manager are at risk due to the stored XSS vulnerability.
CVE-2020-9734 affects Adobe Experience Manager versions 6.5.5.0 and below, as well as 6.4.8.1 and below.
The impact of CVE-2020-9734 allows attackers to store malicious scripts that can execute in victims' browsers, compromising user data and session integrity.