First published: Wed Mar 22 2023(Updated: )
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <6.5.16.0 | |
Adobe Experience Manager | <2023.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the URL Redirection to Untrusted Site vulnerability in Adobe Experience Manager is CVE-2023-22266.
The severity rating of CVE-2023-22266 is medium with a CVSS score of 5.4.
The URL Redirection to Untrusted Site vulnerability in Adobe Experience Manager allows a low-privilege authenticated attacker to redirect users to malicious websites.
Versions 6.5.15.0 and earlier of Adobe Experience Manager are affected by the URL Redirection to Untrusted Site vulnerability.
To fix the URL Redirection to Untrusted Site vulnerability in Adobe Experience Manager, it is recommended to upgrade to version 6.5.16.0 or later.