CyberRota Analysis
AI-GeneratedAdobe Experience Manager is vulnerable to an improper restriction of XML External Entity (XXE) reference, allowing low-privileged attackers to execute arbitrary code within the context of the current user. This could lead to unauthorized access to sensitive files and potentially elevate privileges or control over the victim's account or session, with exploitation possible without user interaction. Organizations using Adobe Experience Manager should prioritize remediation due to the critical severity of this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Related CVEs
Other vulnerabilities affecting the same vendor(s)