CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
arbitrary code execution code execution
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2021-40711
Severity
MEDIUM
CVSS
5.4
EPSS
1.49%
Java
Original NVD Description
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.