6.1
CVE-2020-9743
- EPSS 3.32%
- Veröffentlicht 10.09.2020 17:15:41
- Zuletzt bearbeitet 21.11.2024 05:41:12
- Quelle psirt@adobe.com
- CVE-Watchlists
- Unerledigt
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value. An attacker could then use the malicious GET request to lure victims to perform unsafe actions in the page (ex. phishing).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Experience Manager Version >= 6.3.0.0 <= 6.3.3.8
Adobe ≫ Experience Manager Version >= 6.4.0.0 <= 6.4.8.1
Adobe ≫ Experience Manager Version >= 6.5.0.0 <= 6.5.5.0
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp1
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp10
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp11
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp12.1
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp13
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp14
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp15
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp16
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp17
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp18
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp19
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp2
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp20
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp3
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp4
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp5
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp6
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp7
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp8
Adobe ≫ Experience Manager Version6.2.0.0 Updatesp1-cfp9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.32% | 0.868 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
| psirt@adobe.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.