CVE-2021-40714: Adobe Experience Manager Reflected Cross Site Scripting via accesskey parameter
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the accesskey parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40714?
CVE-2021-40714 is classified as a reflected Cross-Site Scripting (XSS) vulnerability, highlighting a significant security risk.
How do I fix CVE-2021-40714?
To remediate CVE-2021-40714, upgrade to Adobe Experience Manager version 6.5.9.1 or later which includes patches for this vulnerability.
What software versions are affected by CVE-2021-40714?
CVE-2021-40714 affects Adobe Experience Manager versions up to and including 6.5.9.0.
What impact does CVE-2021-40714 have on users?
If exploited, CVE-2021-40714 allows attackers to execute malicious JavaScript in users' browsers, potentially compromising user data.
Is user input a vector for CVE-2021-40714?
Yes, exploitation of CVE-2021-40714 relies on an attacker convincing a victim to click a specifically crafted URL that contains malicious code.