Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2020-24444
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability could be exploited by an unauthenticated attacker to gather information about internal systems that reside on the same network.
0
Attacker Value
Unknown
CVE-2020-9733
Disclosure Date: September 08, 2020 (last updated February 22, 2025)
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
0
Attacker Value
Unknown
CVE-2020-9732
Disclosure Date: September 08, 2020 (last updated February 22, 2025)
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
0
Attacker Value
Unknown
CVE-2019-8089
Disclosure Date: October 22, 2019 (last updated November 27, 2024)
Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2019-7129
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2017-3067
Disclosure Date: May 09, 2017 (last updated November 26, 2024)
Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms.
0
Attacker Value
Unknown
CVE-2016-6934
Disclosure Date: December 15, 2016 (last updated November 25, 2024)
Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.
0