CVE-2025-49552: Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49552?
CVE-2025-49552 is considered a high-severity vulnerability due to its potential for exploitation by high-privileged attackers.
How do I fix CVE-2025-49552?
To address CVE-2025-49552, users should update Adobe Connect to the latest version beyond 12.9.
What kind of attack does CVE-2025-49552 enable?
CVE-2025-49552 enables a DOM-based Cross-Site Scripting (XSS) attack, allowing malicious scripts to execute in a victim's browser.
Which versions of Adobe Connect are affected by CVE-2025-49552?
Adobe Connect versions 12.9 and earlier are affected by CVE-2025-49552.
What is required for exploitation of CVE-2025-49552?
Exploitation of CVE-2025-49552 requires user interaction from the victim.