First published: Tue Dec 10 2024(Updated: )
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. User interaction is required for exploitation, as a victim must visit a malicious link or input data into a vulnerable web application.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <6.5.22.0 | |
Adobe Experience Manager | <2024.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52860 is categorized as a high-severity vulnerability due to its potential for exploitation via DOM-based Cross-Site Scripting.
To fix CVE-2024-52860, upgrade Adobe Experience Manager to version 6.5.22.0 or later.
CVE-2024-52860 affects Adobe Experience Manager versions 6.5.21 and earlier, as well as AEM Cloud Service versions earlier than 2024.11.0.
CVE-2024-52860 is associated with a DOM-based Cross-Site Scripting (XSS) exploit that allows attackers to execute arbitrary code in the victim's browser.
You can confirm if your system is vulnerable to CVE-2024-52860 by checking the version of your Adobe Experience Manager implementation against the affected versions.