CVE-2016-6933 is an input validation vulnerability in the AACComponent of Adobe Experience Manager Forms versions 6.2 and earlier, and Adobe LiveCycle 11.0.1 and 10.0.4, which could lead to cross-site scripting (XSS) attacks. Rated Medium severity with a CVSS score of 6.1, this vulnerability requires user interaction (UI:R) and network access (AV:N) to exploit, potentially resulting in low impact to confidentiality and integrity. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, with limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.0.0:*:*:*:*:*:*:* | ||
6.1.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.1.0:*:*:*:*:*:*:* | ||
6.2.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.2.0:*:*:*:*:*:*:* | ||
10.0.4CPE matchmatch criteria | cpe:2.3:a:adobe:livecycle:10.0.4:*:*:*:*:*:*:* | ||
11.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:livecycle:11.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.