First published: Tue Dec 10 2024(Updated: )
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <6.5.22.0 | |
Adobe Experience Manager | <2024.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43727 has a critical severity rating due to its potential for exploitation through stored Cross-Site Scripting (XSS).
To remediate CVE-2024-43727, upgrade Adobe Experience Manager to version 6.5.22.0 or later, or to version 2024.11.0 or later for AEM Cloud Service.
Adobe Experience Manager versions 6.5.21 and earlier, as well as versions prior to 2024.11.0 for AEM Cloud Service, are affected by CVE-2024-43727.
CVE-2024-43727 is classified as a stored Cross-Site Scripting (XSS) vulnerability.
Attackers can exploit CVE-2024-43727 to inject malicious scripts into form fields, potentially executing unauthorized JavaScript in victims' browsers.