CVE-2023-48477: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48477?
CVE-2023-48477 is classified as a Cross-site Scripting (XSS) vulnerability which allows attackers to execute malicious scripts in the context of the victim's browser.
How does CVE-2023-48477 affect Adobe Experience Manager?
CVE-2023-48477 affects Adobe Experience Manager versions 6.5.18 and earlier, allowing low-privileged attackers to execute malicious JavaScript through crafted URLs.
How can I fix CVE-2023-48477?
To mitigate CVE-2023-48477, upgrade to a version of Adobe Experience Manager later than 6.5.18.
What kind of attacks can be performed using CVE-2023-48477?
Using CVE-2023-48477, an attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to data theft or session hijacking.
Is CVE-2023-48477 present in Adobe Experience Manager Cloud Service?
Yes, CVE-2023-48477 affects Adobe Experience Manager Cloud Service versions prior to 2023.11.