6.1

CVE-2020-9743

AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value. An attacker could then use the malicious GET request to lure victims to perform unsafe actions in the page (ex. phishing).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeExperience Manager Version >= 6.3.0.0 <= 6.3.3.8
AdobeExperience Manager Version >= 6.4.0.0 <= 6.4.8.1
AdobeExperience Manager Version >= 6.5.0.0 <= 6.5.5.0
AdobeExperience Manager Version6.2.0.0 Updatesp1
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp1
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp10
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp11
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp12.1
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp13
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp14
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp15
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp16
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp17
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp18
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp19
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp2
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp20
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp3
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp4
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp5
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp6
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp7
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp8
AdobeExperience Manager Version6.2.0.0 Updatesp1-cfp9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.32% 0.868
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
psirt@adobe.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.