CVE-2019-7953 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Adobe Experience Manager (AEM) versions 6.4 and earlier. This medium-severity vulnerability (CVSS 6.5) allows an unauthenticated attacker to potentially disclose sensitive information in the context of the current user through a low-complexity attack requiring user interaction. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has received some media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, <= 6.4CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.