helpx.adobe.com
https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html CVE-2023-22266
MEDIUM
AEM URL Redirection to Untrusted Site Security feature bypass
Record summary
CVE-2023-22266 has a selected CVSS score of 5.4 (medium).
Description
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Experience ManagerBrowse Adobe / Experience Manager | CVE List | Through 6.5.15.0 | affected |
| Through None | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-22266