First published: Tue Dec 10 2024(Updated: )
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Connect Enterprise Server | <11.4.9 | |
Adobe Connect Enterprise Server | >=12.0<12.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54046 has been categorized as a moderate severity reflected Cross-Site Scripting (XSS) vulnerability.
To mitigate CVE-2024-54046, update Adobe Connect to version 12.7 or later, or to version 11.4.9.
CVE-2024-54046 allows unauthenticated attackers to execute malicious JavaScript within the context of a victim's session by tricking them into visiting a specially crafted URL.
CVE-2024-54046 affects Adobe Connect versions 12.6, 11.4.7 and earlier.
Users of Adobe Connect versions 11.4.7 and earlier, as well as 12.6, are at risk if they are tricked into visiting malicious URLs.