Adobe Experience Manager Reflected XSS in /bin/wcm/contentfinder/page/view.html
Vulnerability Description
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-44178
Credits & Attribution
No credits recorded in the NVD database.
More from Adobe
View All →Affected Vendor
Adobe
View all reports →