CVE-2022-30677: AEM Reflected XSS Arbitrary code execution
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30677?
CVE-2022-30677 is considered a medium severity reflected Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2022-30677?
To mitigate CVE-2022-30677, upgrade Adobe Experience Manager to version 6.5.13.1 or later.
What are the potential impacts of CVE-2022-30677?
Exploitation of CVE-2022-30677 can allow attackers to execute malicious JavaScript in the context of the victim's session.
Who is affected by CVE-2022-30677?
CVE-2022-30677 affects Adobe Experience Manager versions up to 6.5.13.0, including cloud services.
How does the CVE-2022-30677 vulnerability work?
CVE-2022-30677 works by allowing attackers to craft a malicious URL that executes harmful scripts in the victim's browser.