Loading HuntDB...

AEM forms XXE Vulnerability

Critical
A
Adobe
Submitted None

Team Summary

Official summary from Adobe

AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE. CVE: CVE-2021-40722 Ref: https://helpx.adobe.com/security/products/experience-manager/apsb21-103.html We thank @ismailmuh for reporting this to Adobe!

Reported by ismailmuh

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

XML External Entities (XXE)