First published: Tue Aug 24 2021(Updated: )
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <=6.5.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28625 is considered a critical severity vulnerability due to its potential for code execution via Cross-Site Scripting.
To fix CVE-2021-28625, upgrade Adobe Experience Manager to a version higher than 6.5.8.0.
CVE-2021-28625 affects the Adobe Experience Manager Cloud Service offering and versions 6.5.8.0 and below.
CVE-2021-28625 is a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
By exploiting CVE-2021-28625, an attacker could execute malicious JavaScript in a victim's browser through vulnerable form fields.