CVE-2020-9740: Stored XSS in AEM Design Importer Component
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9740?
CVE-2020-9740 is a stored XSS vulnerability in Adobe Experience Manager (AEM) versions 6.5.5.0 and below, 6.4.8.1 and below, 6.3.3.8 and below, and 6.2 SP1-CFP20 and below.
Who is affected by CVE-2020-9740?
Users of Adobe Experience Manager (AEM) versions 6.5.5.0 and below, 6.4.8.1 and below, 6.3.3.8 and below, and 6.2 SP1-CFP20 and below are affected by CVE-2020-9740.
What is the severity of CVE-2020-9740?
The severity of CVE-2020-9740 is critical with a CVSS score of 5.4.
How can I fix CVE-2020-9740?
To fix CVE-2020-9740, users should upgrade to AEM versions 6.5.5.1 (or above), 6.4.8.2 (or above), 6.3.3.9 (or above), or 6.2 SP1-CFP21 (or above) where the vulnerability has been patched.
Where can I find more information about CVE-2020-9740?
You can find more information about CVE-2020-9740 on the Adobe Security Bulletin APSB20-56.