CVE-2016-7885 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Adobe Experience Manager versions 6.2 and earlier. This high-severity flaw (CVSS 8.8) could allow an unauthenticated attacker to compromise confidentiality, integrity, and availability with low attack complexity, requiring user interaction. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.2.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.