CVE-2024-43713
MEDIUMAdobe Experience Manager < 6.5.22.0 and < 2024.11.0 - DOM-based Cross-Site Scripting via Crafted URL
Title source: llmDescription
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to access a manipulated URL or page with the malicious script.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html
Scores
CVSS v3
5.4
EPSS
0.0081
EPSS Percentile
74.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
adobe/experience_manager
< 2024.11.0
adobe/experience_manager
< 6.5.22.0
Published
Dec 10, 2024
Tracked Since
Feb 18, 2026