QID 981988

QID 981988: Java (maven) Security Update for com.adobe.acs:acs-aem-commons (GHSA-7r83-w6r8-fh6w)

ACS Commons version 4.9.2 (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in version-compare and page-compare due to invalid JCR characters that are not handled correctly. An attacker could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable form fields and execute it within the context of the victim's browser. Exploitation of this issue requires user interaction in order to be successful.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-7r83-w6r8-fh6w for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981988

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7r83-w6r8-fh6w com.adobe.acs:acs-aem-commons URL Logo github.com/advisories/GHSA-7r83-w6r8-fh6w