
CVE-2024-54038 – Adobe Connect | Improper Access Control (CWE-284)
https://notcve.org/view.php?id=CVE-2024-54038
10 Dec 2024 — Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage... • https://helpx.adobe.com/security/products/connect/apsb24-99.html • CWE-284: Improper Access Control •

CVE-2024-54032 – Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
https://notcve.org/view.php?id=CVE-2024-54032
10 Dec 2024 — Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into v... • https://helpx.adobe.com/security/products/connect/apsb24-99.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-54046 – Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
https://notcve.org/view.php?id=CVE-2024-54046
10 Dec 2024 — Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerab... • https://helpx.adobe.com/security/products/connect/apsb24-99.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-29305 – Adobe Connect Reflected Cross-Site Scripting (XSS) Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-29305
13 Sep 2023 — Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Las versiones 12.3 y anteriores de Adobe Connect se ven afectadas por una vulnerabilidad Cross-Site Scripting (XSS) Reflejada. Si un atacante puede convencer a una víctima para que visite una URL que haga referencia a una p... • https://helpx.adobe.com/security/products/connect/apsb23-33.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-29306 – Adobe Connect Reflected Cross-Site Scripting (XSS) Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-29306
13 Sep 2023 — Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Las versiones 12.3 y anteriores de Adobe Connect se ven afectadas por una vulnerabilidad Cross-Site Scripting (XSS) Reflejada. Si un atacante puede convencer a una víctima para que visite una URL que haga referencia a una p... • https://helpx.adobe.com/security/products/connect/apsb23-33.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-22232 – Adobe Connect Improper Access Control Security feature bypass
https://notcve.org/view.php?id=CVE-2023-22232
17 Feb 2023 — Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction. Adobe Connect versions 11.4.5 and below as well as versions 12.1.5 and below suffer from a file disclosure vulnerability. • https://packetstorm.news/files/id/171390 • CWE-284: Improper Access Control •

CVE-2021-40719 – Adobe Connect Deserialization of Untrusted Data Remote Code Execution
https://notcve.org/view.php?id=CVE-2021-40719
21 Oct 2021 — Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation when AMF messages are deserialized on an Adobe Connect server. An attacker can leverage this to execute remote code execution on the server. Adobe Connect versiones 11.2.3 de Adobe Connect (y anteriores) se ve afectada por una vulnerabilidad de Deserialización de datos no confiables para lograr la invocación de métodos arbitrarios cuando los mensajes AMF se deser... • https://helpx.adobe.com/security/products/connect/apsb21-91.html • CWE-502: Deserialization of Untrusted Data •

CVE-2021-40721 – Adobe Connect Reflected Cross Site Scripting
https://notcve.org/view.php?id=CVE-2021-40721
15 Oct 2021 — Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. La versión 11.2.3 de Adobe Connect (y anteriores) está afectada por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) reflejada. Si un atacante es capaz de convencer a una víctima de que visite una URL... • https://helpx.adobe.com/security/products/connect/apsb21-91.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-36063 – Adobe Connect Reflected Cross-site Scripting via 'isTabletDeviceHTML' parameter
https://notcve.org/view.php?id=CVE-2021-36063
01 Sep 2021 — Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Adobe Connect versiones 11.2.2 (y anteriores), está afectada por una vulnerabilidad de tipo Cross-site Scripting Reflejado que podría ser abusado por un atacante para inyectar scripts malicioso... • https://helpx.adobe.com/security/products/connect/apsb21-66.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-36061 – Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordings
https://notcve.org/view.php?id=CVE-2021-36061
01 Sep 2021 — Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment. Exploitation of this issue requires user interaction in that a victim must publish a link of a Connect recording. Adobe Connect versiones 11.2.2 (y anteriores), está afectada por una vulnerabilidad de violación de los principios de diseño seguro por medio ... • https://helpx.adobe.com/security/products/connect/apsb21-66.html • CWE-657: Violation of Secure Design Principles •