First published: Tue Dec 10 2024(Updated: )
Adobe Experience Manager versions 6.5.21 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <6.5.22.0 | |
Adobe Experience Manager | <2024.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43745 is categorized as a reflected Cross-Site Scripting (XSS) vulnerability, which can pose significant security risks to users.
To fix CVE-2024-43745, upgrade Adobe Experience Manager to version 6.5.22.0 or later, or to version 2024.11.0 or later.
Adobe Experience Manager versions 6.5.21 and earlier, as well as all versions prior to 2024.11.0, are affected by CVE-2024-43745.
An attacker exploiting CVE-2024-43745 can execute malicious JavaScript content within the context of a user's session if they trick the user into visiting a vulnerable URL.
CVE-2024-43745 is classified as a reflected Cross-Site Scripting (XSS) vulnerability.