QID 730231
Date Published: 2021-10-13
QID 730231: Adobe Connect Multiple Vulnerabilities (APSB21-91)
Adobe Connect is software used to create information and general presentations, online training materials, web conferencing, learning modules, and user desktop sharing.
CVE-2021-40719: Deserialization of Untrusted Data
CVE-2021-40721: Cross-site Scripting (Reflected XSS)
Affected Versions:
Adobe Connect 11.2.2 and earlier versions
QID Detection Logic (Unauthenticated):
his QID reads the version.txt file in an unauthenticated request to see if it's vulnerable.
Successful exploitation of these vulnerability may allow an attacker to execute arbitrary code on the target system.
Solution
Customers are advised to follow the patch procedure provided by Adobe. Furthermore information can be obtained from Adobe Connect 11.2.3
Vendor References
CVEs related to QID 730231
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| APSB21-91 |
|