CVE-2025-54256: Dreamweaver Desktop | Cross-Site Request Forgery (CSRF) (CWE-352)
Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must click on a malicious link, and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54256?
CVE-2025-54256 is classified as a medium severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2025-54256?
To remediate CVE-2025-54256, upgrade Adobe Dreamweaver Desktop to version 21.6 or later.
What type of vulnerability is CVE-2025-54256?
CVE-2025-54256 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2025-54256?
CVE-2025-54256 affects users of Adobe Dreamweaver Desktop versions 21.5 and earlier.
What user action is needed to exploit CVE-2025-54256?
Exploitation of CVE-2025-54256 requires user interaction, specifically that the victim clicks on a malicious link.