CVE-2020-9737 is a stored Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager (AEM) versions 6.5.5.0 and below, 6.4.8.1 and below, 6.3.3.8 and below, and 6.2 SP1-CFP20 and below. This medium-severity vulnerability (CVSS 4.8) allows authenticated users with Content Repository Development Environment access to inject malicious scripts into node fields, which execute in a victim's browser upon page access. While the vulnerability requires high privileges and user interaction, it can lead to limited impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, with minimal community discussion and limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3.0.0, <= 6.3.3.8CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* | ||
>= 6.4.0.0, <= 6.4.8.1CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* | ||
>= 6.5.0.0, <= 6.5.5.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* | ||
6.2.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1:*:*:*:*:*:* | ||
6.2.0.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.