Show plain JSON{"id": "CVE-2021-21084", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Secondary", "source": "psirt@adobe.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.3, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.2, "exploitabilityScore": 2.1}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 6.1, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.8}]}, "published": "2021-06-28T14:15:09.043", "references": [{"url": "https://helpx.adobe.com/security/products/experience-manager/apsb21-15.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "psirt@adobe.com"}, {"url": "https://helpx.adobe.com/security/products/experience-manager/apsb21-15.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "psirt@adobe.com", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim\u2019s browser when they browse to the page containing the vulnerable field."}, {"lang": "es", "value": "AEM oferta de Servicios en la Nube, as\u00ed como las versiones 6.5.7.0 (y posteriores), versiones 6.4.8.3 (y posteriores) y versiones 6.3.3.8 (y posteriores), est\u00e1n afectadas por una vulnerabilidad de tipo Cross-Site Scripting (XSS) almacenado que podr\u00eda ser abusada por un atacante para inyectar scripts maliciosos en campos de formularios vulnerables. El JavaScript malicioso podr\u00eda ser ejecutado en el navegador de la v\u00edctima cuando \u00e9sta navega a la p\u00e1gina que contiene el campo vulnerable"}], "lastModified": "2024-11-21T05:47:32.053", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47328F6D-4225-4021-B5A4-F111A07E6B92", "versionEndIncluding": "6.3.3.8"}, {"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F36EEFB5-68FB-45F7-A4EF-ACA58D400B64", "versionEndExcluding": "6.4.8.4", "versionStartIncluding": "6.4.0.0"}, {"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50AC31ED-B042-4628-83B7-4CA4703873B5", "versionEndExcluding": "6.5.8.0", "versionStartIncluding": "6.5.0.0"}, {"criteria": "cpe:2.3:a:adobe:experience_manager_cloud_service:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "360F2694-4E6F-4D0C-9218-CD0450506AB6"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@adobe.com"}