CVE-2021-21043
Summary
| CVE | CVE-2021-21043 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-02 23:15:00 UTC |
| Updated | 2021-12-10 19:46:00 UTC |
| Description | ACS Commons version 4.9.2 (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in version-compare and page-compare due to invalid JCR characters that are not handled correctly. An attacker could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable form fields and execute it within the context of the victim's browser. Exploitation of this issue requires user interaction in order to be successful. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Adobe Security Bulletin |
MISC |
helpx.adobe.com |
|
| CVE-2021-21043: Reflected Cross-site Scripting (XSS) on version-compare and page-compare tools. · Advisory · Adobe-Consulting-Services/acs-aem-commons · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375549 Adobe InDesign Arbitrary Code Execution Vulnerability (APSB21-22)
- 981988 Java (maven) Security Update for com.adobe.acs:acs-aem-commons (GHSA-7r83-w6r8-fh6w)