CVE-2020-9736: Stored XSS in AEM's Content Repository Development Environment
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when browsing to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9736?
CVE-2020-9736 is classified as a medium-severity stored XSS vulnerability.
How do I fix CVE-2020-9736?
To fix CVE-2020-9736, upgrade to Adobe Experience Manager version 6.5.5.1 or later, or versions 6.4.8.2 and 6.3.3.9.
Which versions of Adobe Experience Manager are affected by CVE-2020-9736?
Affected versions include Adobe Experience Manager 6.5.5.0 and below, 6.4.8.1 and below, 6.3.3.8 and below, and 6.2 SP1-CFP20 and below.
What type of vulnerability is CVE-2020-9736?
CVE-2020-9736 is a stored cross-site scripting (XSS) vulnerability.
Can a user exploit CVE-2020-9736 remotely?
Yes, a user with access to the Content Repository Development Environment can exploit CVE-2020-9736 to store malicious scripts.