CVE-2024-26091

MEDIUM

Adobe Experience Manager < 6.5.21 and < 2024.5 - DOM-based Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires user interaction, such as convincing a victim to click on a specially crafted link or to submit a form that causes the vulnerable script to execute.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0171
EPSS Percentile 82.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
adobe/experience_manager < 2024.5
adobe/experience_manager < 6.5.21
Published Jun 13, 2024
Tracked Since Feb 18, 2026