First published: Tue May 13 2025(Updated: )
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Connect Enterprise Server | <=12.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43567 has been classified as a medium severity vulnerability due to the potential for reflected Cross-Site Scripting attacks.
To mitigate CVE-2025-43567, users should update Adobe Connect to version 12.9 or later.
CVE-2025-43567 is a reflected Cross-Site Scripting (XSS) vulnerability.
Adobe Connect versions 12.8 and earlier are affected by CVE-2025-43567.
An attacker could use CVE-2025-43567 to inject malicious scripts into form fields, potentially executing JavaScript in a victim's browser.