CVE-2023-48506: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48506?
CVE-2023-48506 is considered a medium severity vulnerability due to its potential for exploitation through stored XSS.
How do I fix CVE-2023-48506?
To fix CVE-2023-48506, upgrade Adobe Experience Manager to version 6.5.19 or later, or to a version beyond 2023.11 for the cloud service.
Who is affected by CVE-2023-48506?
CVE-2023-48506 affects users of Adobe Experience Manager versions 6.5.18 and earlier, as well as those on Adobe Experience Manager Cloud Service prior to version 2023.11.
What kind of attacks can CVE-2023-48506 facilitate?
CVE-2023-48506 can facilitate stored Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into form fields.
What are the impacts of CVE-2023-48506?
The impacts of CVE-2023-48506 include the execution of malicious JavaScript in a victim's browser, which can compromise user data and session integrity.