First published: Wed Sep 01 2021(Updated: )
Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Connect | <=11.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36062 is a vulnerability in Adobe Connect version 11.2.2 (and earlier) that allows for a Reflected Cross-site Scripting attack.
CVE-2021-36062 affects Adobe Connect version 11.2.2 (and earlier) by allowing an attacker to inject malicious scripts into vulnerable form fields through a Reflected Cross-site Scripting vulnerability.
The severity of CVE-2021-36062 is medium with a CVSS score of 6.1.
An attacker can exploit CVE-2021-36062 by convincing a victim to visit a URL that references a vulnerable page, which then allows the injection of malicious JavaScript code into the form fields.
Yes, Adobe has released a security update to fix the CVE-2021-36062 vulnerability in Adobe Connect. It is recommended to update to the latest version.