First published: Tue Dec 14 2021(Updated: )
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <=6.5.10.0 | |
Adobe Experience Manager Cloud Service |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44178 has been rated as a critical severity vulnerability due to its potential impact on user data and security.
To mitigate CVE-2021-44178, update Adobe Experience Manager to version 6.5.10.1 or higher, or implement recommended security practices.
CVE-2021-44178 is classified as a reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2021-44178 affects Adobe Experience Manager Cloud Service and versions of Adobe Experience Manager up to 6.5.10.0.
An attacker exploiting CVE-2021-44178 can execute malicious JavaScript in the context of the victim's browser by convincing them to visit a specially crafted URL.