CVE-2021-28628: Adobe Experience Manager Cross-site Scripting vulnerability in inbox render.jsp
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28628?
CVE-2021-28628 is considered a critical vulnerability due to its potential for exploitation via Cross-Site Scripting (XSS).
How do I fix CVE-2021-28628?
To mitigate CVE-2021-28628, upgrade Adobe Experience Manager to version 6.5.8.1 or later, or apply the necessary patches provided by Adobe.
What versions of Adobe Experience Manager are affected by CVE-2021-28628?
CVE-2021-28628 affects Adobe Experience Manager versions 6.5.8.0 and lower as well as the Adobe Experience Manager Cloud Service.
What type of vulnerability is CVE-2021-28628?
CVE-2021-28628 is classified as a Cross-Site Scripting (XSS) vulnerability which allows attackers to inject malicious scripts.
Can CVE-2021-28628 lead to data breaches?
Yes, exploitation of CVE-2021-28628 can lead to data breaches by executing malicious JavaScript in the context of the user's session.