CVE-2020-9738: Stored XSS in AEM's Content Repository Development Environment
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when visiting the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9738?
CVE-2020-9738 has a high severity rating due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2020-9738?
To fix CVE-2020-9738, you should upgrade Adobe Experience Manager to the latest patched version.
Which versions of Adobe Experience Manager are affected by CVE-2020-9738?
CVE-2020-9738 affects Adobe Experience Manager versions 6.5.5.0 and below, 6.4.8.1 and below, 6.3.3.8 and below, and 6.2 SP1-CFP20 and below.
What type of vulnerability is CVE-2020-9738?
CVE-2020-9738 is a stored cross-site scripting (XSS) vulnerability.
Can CVE-2020-9738 be exploited remotely?
Yes, CVE-2020-9738 can be exploited remotely by attackers who have access to the Content Repository Development Environment.