First published: Tue Aug 24 2021(Updated: )
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <=6.5.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28628 is considered a critical vulnerability due to its potential for exploitation via Cross-Site Scripting (XSS).
To mitigate CVE-2021-28628, upgrade Adobe Experience Manager to version 6.5.8.1 or later, or apply the necessary patches provided by Adobe.
CVE-2021-28628 affects Adobe Experience Manager versions 6.5.8.0 and lower as well as the Adobe Experience Manager Cloud Service.
CVE-2021-28628 is classified as a Cross-Site Scripting (XSS) vulnerability which allows attackers to inject malicious scripts.
Yes, exploitation of CVE-2021-28628 can lead to data breaches by executing malicious JavaScript in the context of the user's session.