CVE-2020-9735 is a stored Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager (AEM) versions 6.5.5.0 and below, 6.4.8.1 and below, 6.3.3.8 and below, and 6.2 SP1-CFP20 and below. This vulnerability allows highly privileged users with access to the Content Repository Development Environment to inject malicious scripts into specific node fields. The scripts execute in a victim's browser when search queries display the affected page. The vulnerability has a CVSS score of 4.8 (Medium), indicating a network attack vector, low attack complexity, and requiring high privileges and user interaction, with potential for limited confidentiality and integrity impact. It is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article found, suggesting low public awareness and limited attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3.0.0, <= 6.3.3.8CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* | ||
>= 6.4.0.0, <= 6.4.8.1CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* | ||
>= 6.5.0.0, <= 6.5.5.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* | ||
6.2.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1:*:*:*:*:*:* | ||
6.2.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.