CVE-2024-36197

MEDIUM

Adobe Experience Manager <6.5.20 - XSS

Title source: llm
STIX 2.1

Description

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a specially crafted link or to submit a form that triggers the vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0231
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
adobe/experience_manager < 2024.5
adobe/experience_manager < 6.5.21
Published Jun 13, 2024
Tracked Since Feb 18, 2026