CVE-2024-54046: Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54046?
CVE-2024-54046 has been categorized as a moderate severity reflected Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-54046?
To mitigate CVE-2024-54046, update Adobe Connect to version 12.7 or later, or to version 11.4.9.
What types of attacks can be performed using CVE-2024-54046?
CVE-2024-54046 allows unauthenticated attackers to execute malicious JavaScript within the context of a victim's session by tricking them into visiting a specially crafted URL.
Which versions of Adobe Connect are affected by CVE-2024-54046?
CVE-2024-54046 affects Adobe Connect versions 12.6, 11.4.7 and earlier.
Who is at risk from CVE-2024-54046?
Users of Adobe Connect versions 11.4.7 and earlier, as well as 12.6, are at risk if they are tricked into visiting malicious URLs.