CVE-2020-9734: Stored XSS in AEM Forms component
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9734?
CVE-2020-9734 is classified as a stored Cross-Site Scripting (XSS) vulnerability which poses a significant security risk to affected versions.
How do I fix CVE-2020-9734?
To mitigate CVE-2020-9734, update Adobe Experience Manager to version 6.5.5.1 or later, or 6.4.8.2 or later.
Who is affected by CVE-2020-9734?
Users with 'Author' privileges on affected versions of Adobe Experience Manager are at risk due to the stored XSS vulnerability.
What are the affected versions for CVE-2020-9734?
CVE-2020-9734 affects Adobe Experience Manager versions 6.5.5.0 and below, as well as 6.4.8.1 and below.
What is the impact of CVE-2020-9734?
The impact of CVE-2020-9734 allows attackers to store malicious scripts that can execute in victims' browsers, compromising user data and session integrity.