CVE-2016-7851 describes a cross-site scripting (XSS) vulnerability in Adobe Connect versions 9.5.6 and earlier, stemming from insufficient input validation in the events registration module. This medium-severity flaw (CVSS 6.1) could allow an unauthenticated attacker to inject malicious scripts, potentially leading to information disclosure or defacement, requiring user interaction to succeed. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB, and it has received some community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.5.6CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.