First published: Mon Dec 19 2022(Updated: )
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <6.5.15.0 | |
Adobe Experience Manager Cloud Service | <2022.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42356 is a reflected Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager version 6.5.14 and earlier.
CVE-2022-42356 has a severity rating of 5.4 (medium).
Adobe Experience Manager version 6.5.14 and earlier, as well as Adobe Experience Manager Cloud Service version 2022.10.0 and earlier, are affected by CVE-2022-42356.
If a low-privileged attacker can convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's session.
Update to Adobe Experience Manager version 6.5.15.0 or later, or Adobe Experience Manager Cloud Service version 2022.10.1 or later, to mitigate CVE-2022-42356.