QID 150418
Date Published: 2022-02-15
QID 150418: Adobe Experience Manager: WCM Debug Filter Exposed
WCM Debug Filter is exposed. References: https://github.com/0ang3el/aem-hacker https://www.slideshare.net/0ang3el/presentations
WCMDebugFilter might be vulnerable to reflected XSS (CVE-2016-7882). See - https://medium.com/@jonathanbouman/reflected-xss-at-philips-com-e48bf8f9cd3c.
Solution
This filter is disabled by default on published instances of AEM version 6.0 or higher. Please refer to the Adobe configuration guide and security checklist for more details.
Vendor References
CVEs related to QID 150418
Software Advisories
| Advisory ID | Software | Component | Link |
|---|