CVE-2022-34218: AEM Reflected XSS Arbitrary code execution
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34218?
CVE-2022-34218 has been rated as a medium severity reflected Cross-Site Scripting vulnerability.
How do I fix CVE-2022-34218?
To fix CVE-2022-34218, upgrade Adobe Experience Manager to version 6.5.13.1 or later.
What versions of Adobe Experience Manager are affected by CVE-2022-34218?
CVE-2022-34218 affects Adobe Experience Manager versions up to and including 6.5.13.0.
What type of attack is possible with CVE-2022-34218?
CVE-2022-34218 allows an attacker to execute malicious JavaScript in the context of the victim's browser through a reflected XSS attack.
Who can be impacted by CVE-2022-34218?
Users visiting compromised URLs may be impacted by CVE-2022-34218 if they are using affected versions of Adobe Experience Manager.