CVE-2021-40711: Adobe Experience Manager Stored Cross-Site Scripting Could Lead to Arbitrary Code Execution
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40711?
CVE-2021-40711 is classified as a medium severity vulnerability.
How does CVE-2021-40711 occur?
CVE-2021-40711 occurs due to stored XSS when creating Content Fragments in Adobe Experience Manager.
Who is affected by CVE-2021-40711?
CVE-2021-40711 affects authenticated users of Adobe Experience Manager version 6.5.9.0 and earlier.
How do I fix CVE-2021-40711?
To fix CVE-2021-40711, update Adobe Experience Manager to the latest version beyond 6.5.9.0.
What impact does CVE-2021-40711 have on users?
CVE-2021-40711 can lead to arbitrary code execution and malicious JavaScript being executed in a victim's browser.