CVE-2024-36220

MEDIUM

Adobe Experience Manager <6.5.20 - XSS

Title source: llm
STIX 2.1

Description

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a specially crafted link or to submit a form that triggers the malicious script.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0640
EPSS Percentile 91.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
adobe/experience_manager < 2024.5
adobe/experience_manager < 6.5.21
Published Jun 13, 2024
Tracked Since Feb 18, 2026