CVE-2025-49553: Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49553?
CVE-2025-49553 is rated as a high severity vulnerability due to its potential for exploitation through Cross-Site Scripting.
How do I fix CVE-2025-49553?
To fix CVE-2025-49553, update Adobe Connect to version 12.10 or later.
What types of attacks does CVE-2025-49553 allow?
CVE-2025-49553 allows attackers to execute malicious scripts in a victim's browser, leading to unauthorized actions.
What versions of Adobe Connect are affected by CVE-2025-49553?
Adobe Connect versions 12.9 and earlier are affected by CVE-2025-49553.
What is a prerequisite for exploiting CVE-2025-49553?
Exploitation of CVE-2025-49553 requires user interaction, as the victim must navigate to a malicious site.