CVE-2024-54039: Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54039?
CVE-2024-54039 is classified as a high severity vulnerability due to its potential for exploitation through stored Cross-Site Scripting.
How do I fix CVE-2024-54039?
To fix CVE-2024-54039, update Adobe Connect to version 12.7 or later for affected versions prior to this update.
Which Adobe Connect versions are impacted by CVE-2024-54039?
Adobe Connect versions 12.6, all versions of 11.4 up to 11.4.7, and earlier are impacted by CVE-2024-54039.
What type of vulnerability is CVE-2024-54039?
CVE-2024-54039 is a stored Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
What could an attacker do by exploiting CVE-2024-54039?
By exploiting CVE-2024-54039, an attacker could execute malicious JavaScript in a victim's browser, potentially compromising sensitive information.