CVE-2023-29306: Adobe Connect Reflected Cross-Site Scripting (XSS) Arbitrary code execution
Published Sep 13, 2023
·Updated
Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Affected Software
1 affected component
Adobe Connect<=12.3
Event History
Sep 13, 2023
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Adobe Connect vulnerability?
The vulnerability ID for this Adobe Connect vulnerability is CVE-2023-29306.
2
What is the severity rating of CVE-2023-29306?
The severity rating of CVE-2023-29306 is medium with a CVSS score of 6.1.
3
Which versions of Adobe Connect are affected by CVE-2023-29306?
Adobe Connect versions 12.3 and earlier are affected by CVE-2023-29306.
4
What is the impact of CVE-2023-29306?
CVE-2023-29306 allows an attacker to execute malicious JavaScript within the victim's browser.
5
Is there a fix available for CVE-2023-29306?
Yes, Adobe has released a security update to address the vulnerability. Please refer to the official Adobe security advisory for more information.