CVE-2021-36062: Adobe Connect Reflected Cross-site Scripting via 'campaign-id' parameter
Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-36062?
CVE-2021-36062 is a vulnerability in Adobe Connect version 11.2.2 (and earlier) that allows for a Reflected Cross-site Scripting attack.
How does CVE-2021-36062 affect Adobe Connect?
CVE-2021-36062 affects Adobe Connect version 11.2.2 (and earlier) by allowing an attacker to inject malicious scripts into vulnerable form fields through a Reflected Cross-site Scripting vulnerability.
What is the severity of CVE-2021-36062?
The severity of CVE-2021-36062 is medium with a CVSS score of 6.1.
How can an attacker exploit CVE-2021-36062?
An attacker can exploit CVE-2021-36062 by convincing a victim to visit a URL that references a vulnerable page, which then allows the injection of malicious JavaScript code into the form fields.
Is there a fix available for CVE-2021-36062?
Yes, Adobe has released a security update to fix the CVE-2021-36062 vulnerability in Adobe Connect. It is recommended to update to the latest version.