CVE-2016-4164 describes a cross-site scripting (XSS) vulnerability in Adobe Brackets versions prior to 1.7, allowing remote attackers to inject arbitrary web script or HTML through unspecified vectors. This medium-severity vulnerability has a CVSS score of 6.1, indicating a low impact on confidentiality and integrity, and requires user interaction for successful exploitation. While there is no known exploit code available in common databases like Metasploit or ExploitDB, and it is not listed in the KEV catalog, community discussion and media coverage suggest some awareness, including a mention in a SecurityWeek article about a Flash zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6CPE matchmatch criteria | cpe:2.3:a:adobe:brackets:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.