CVE-2023-22262 – AEM URL Redirection to Untrusted Site Security feature bypass
https://notcve.org/view.php?id=CVE-2023-22262
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction. • https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2023-22263 – AEM URL Redirection to Untrusted Site Security feature bypass
https://notcve.org/view.php?id=CVE-2023-22263
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction. • https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2023-22253 – AEM Reflected XSS Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-22253
Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. • https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-22254 – AEM Reflected XSS Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-22254
Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. • https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-22252 – AEM Reflected XSS Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-22252
Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. • https://helpx.adobe.com/security/products/experience-manager/apsb23-18.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •