
Cloud Vulnerability DB
A community-led vulnerabilities database
The AEM Forms add-on for Adobe Experience Manager versions 6.5.5.0 (and below) and 6.4.8.1 (and below) was affected by a stored Cross-Site Scripting (XSS) vulnerability. The vulnerability allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component, which could then be executed in a victim's browser when they open the page containing the vulnerable field (NVD).
The vulnerability is classified as a Cross-Site Scripting (CWE-79) issue that enables arbitrary JavaScript execution in the browser. Adobe assigned this vulnerability a CVSS v3.1 base score of 9.0 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H, while NIST NVD rated it at 5.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N (NVD, Adobe Advisory).
Successful exploitation of this vulnerability could result in arbitrary JavaScript execution in the victim's browser, potentially leading to sensitive information disclosure or account compromise. The vulnerability requires user interaction and authenticated access with Author privileges to exploit (Threatpost).
The vulnerability requires an attacker to have Author privileges in the AEM Forms system and a victim to access a page containing the malicious script. Adobe classified this with a Priority 2 rating, indicating that while the product has historically been at elevated risk, there were no known exploits in the wild at the time of disclosure (Adobe Advisory).
Adobe released fixes for this vulnerability in AEM Forms Service Pack 6 for version 6.5.6.0 and version 6.4.8.2. Adobe recommended administrators install the update within 30 days of release (Adobe Advisory).
The vulnerability was disclosed as part of Adobe's September 2020 security updates, which addressed multiple critical XSS flaws in Experience Manager. Security researchers noted the importance of patching these vulnerabilities promptly due to the widespread use of these tools in marketing and their access to critical information (Threatpost).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."