CVE-2021-28625: Adobe Experience Manager Cross-site Scripting vulnerability in inbox workitem.jsp
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28625?
CVE-2021-28625 is considered a critical severity vulnerability due to its potential for code execution via Cross-Site Scripting.
How do I fix CVE-2021-28625?
To fix CVE-2021-28625, upgrade Adobe Experience Manager to a version higher than 6.5.8.0.
What does CVE-2021-28625 affect?
CVE-2021-28625 affects the Adobe Experience Manager Cloud Service offering and versions 6.5.8.0 and below.
What type of vulnerability is CVE-2021-28625?
CVE-2021-28625 is a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
What could an attacker do by exploiting CVE-2021-28625?
By exploiting CVE-2021-28625, an attacker could execute malicious JavaScript in a victim's browser through vulnerable form fields.