CVE-2022-30680: AEM Reflected XSS Arbitrary code execution
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30680?
CVE-2022-30680 is classified as a high severity reflected Cross-Site Scripting vulnerability.
How do I fix CVE-2022-30680?
To mitigate CVE-2022-30680, users should update to Adobe Experience Manager version 6.5.14.0 or later.
What types of attacks can exploit CVE-2022-30680?
CVE-2022-30680 can be exploited for executing malicious JavaScript code in the victim's browser.
Which versions of Adobe Experience Manager are affected by CVE-2022-30680?
CVE-2022-30680 affects Adobe Experience Manager versions 6.5.13.0 and earlier.
Is Adobe Experience Manager Cloud Service affected by CVE-2022-30680?
The Adobe Experience Manager Cloud Service is also affected by CVE-2022-30680.