CVE-2024-36181

MEDIUM

Adobe Experience Manager <6.5.20 - XSS

Title source: llm
STIX 2.1

Description

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue requires user interaction, typically in the form of convincing a victim to visit a maliciously crafted web page or to interact with a maliciously modified DOM element within the application.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0240
EPSS Percentile 85.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
adobe/experience_manager < 2024.5
adobe/experience_manager < 6.5.21
Published Jun 13, 2024
Tracked Since Feb 18, 2026