First published: Tue Dec 10 2024(Updated: )
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the high-privileged attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to visit a malicious link or input data into a compromised form. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Connect Enterprise Server | <11.4.9 | |
Adobe Connect Enterprise Server | >=12.0<12.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54037 is considered a critical vulnerability due to its potential for remote code execution via Cross-Site Scripting.
To fix CVE-2024-54037, upgrade Adobe Connect to version 12.7 or later, or to version 11.4.9 or later.
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by CVE-2024-54037.
Yes, CVE-2024-54037 can be exploited remotely by an attacker through maliciously crafted URLs.
CVE-2024-54037 is a DOM-based Cross-Site Scripting (XSS) vulnerability.