CVE-2020-9743
HTML injection in AEM's content editor component
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value. An attacker could then use the malicious GET request to lure victims to perform unsafe actions in the page (ex. phishing).
AEM versiones 6.5.5.0 (y anteriores), 6.4.8.1 (y anteriores), 6.3.3.8 (y anteriores) y 6.2 SP1-CFP20 (y posteriores), están afectadas por una vulnerabilidad de inyección HTML en el componente content editor que permite a usuarios no autenticados diseñar una petición HTTP que incluya código HTML arbitrario en un valor de parámetro. Un atacante podría utilizar la petición GET maliciosa para atraer a las víctimas a llevar a cabo acciones no seguras en la página (por ejemplo, phishing)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-02 CVE Reserved
- 2020-09-10 CVE Published
- 2023-04-17 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/experience-manager/apsb20-56.html | 2021-09-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | >= 6.3.0.0 <= 6.3.3.8 Search vendor "Adobe" for product "Experience Manager" and version " >= 6.3.0.0 <= 6.3.3.8" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | >= 6.4.0.0 <= 6.4.8.1 Search vendor "Adobe" for product "Experience Manager" and version " >= 6.4.0.0 <= 6.4.8.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | >= 6.5.0.0 <= 6.5.5.0 Search vendor "Adobe" for product "Experience Manager" and version " >= 6.5.0.0 <= 6.5.5.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp10 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp11 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp12.1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp13 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp14 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp15 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp16 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp17 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp18 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp19 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp20 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp5 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp6 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp7 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp8 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | 6.2.0.0 Search vendor "Adobe" for product "Experience Manager" and version "6.2.0.0" | sp1-cfp9 |
Affected
|