Vulnerability Description
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, an attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Experience Manager | < 6.5.22.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-43720?
CVE-2024-43720 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim...
How severe is CVE-2024-43720?
CVE-2024-43720 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43720?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Experience Manager.