QID 730152
Date Published: 2021-08-11
QID 730152: Adobe Connect Multiple Vulnerabilities (APSB21-66)
Adobe Connect is software used to create information and general presentations, online training materials, web conferencing, learning modules, and user desktop sharing.
CVE-2021-36061 - Violation of Secure Design Principles
CVE-2021-36062,CVE-2021-36063 - Cross-site Scripting (Reflected XSS)
Affected Versions:
Adobe Connect 11.2.2 and earlier versions
QID Detection Logic (Unauthenticated):
his QID reads the version.txt file in an unauthenticated request to see if it's vulnerable.
On Successful exploitation, the attacker would be able to execute arbitrary code on the target.
Solution
Customers are advised to follow the patch procedure provided by Adobe. Furthermore information can be obtained from Adobe Connect 11.2.3
Vendor References
CVEs related to QID 730152
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| APSB21-66 |
|