First published: Mon Dec 19 2022(Updated: )
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <6.5.15.0 | |
Adobe Experience Manager Cloud Service | <2022.10.0 | |
<6.5.15.0 | ||
<2022.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-44463 is medium with a CVSS score of 5.4.
The reflected Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager version 6.5.14 (and earlier) allows a low-privileged attacker to execute malicious JavaScript within the context of the victim's visit if they can convince the victim to visit a URL referencing a vulnerable page.
Adobe Experience Manager version 6.5.14 (and earlier) and Adobe Experience Manager Cloud Service version up to 2022.10.0 are affected by CVE-2022-44463.
To fix the reflected Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager, it is recommended to upgrade to version 6.5.15.0 for Adobe Experience Manager or to version 2022.10.0 for Adobe Experience Manager Cloud Service.
More information about CVE-2022-44463 can be found at the following link: [Adobe Security Bulletin APSB22-59](https://helpx.adobe.com/security/products/experience-manager/apsb22-59.html).