CVE-2021-44178
Adobe Experience Manager Reflected XSS in /bin/wcm/contentfinder/page/view.html
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser
AEM's Cloud Service offering, así como la versión 6.5.10.0 (y anteriores) están afectadas por una vulnerabilidad de tipo Cross-Site Scripting (XSS) reflejada por medio del parámetro itemResourceType. Si un atacante es capaz de convencer a una víctima de que visite una URL que haga referencia a una página vulnerable, puede ejecutarse contenido JavaScript malicioso en el contexto del navegador de la víctima
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-23 CVE Reserved
- 2022-01-13 CVE Published
- 2024-07-20 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/experience-manager/apsb21-103.html | 2022-01-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | <= 6.5.10.0 Search vendor "Adobe" for product "Experience Manager" and version " <= 6.5.10.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Cloud Service Search vendor "Adobe" for product "Experience Manager Cloud Service" | - | - |
Affected
|