CVE-2021-21079

MEDIUM

Adobe Connect < 11.0.7 - Reflected Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious JavaScript content that may be executed within the context of the victim's browser when they browse to the page containing the vulnerable field.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0112
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
adobe/connect < 11.0.7
Published Mar 12, 2021
Tracked Since Feb 18, 2026