« Back to list

CVE-2020-9743

Status: ModifiedMedium (6.1)—

AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value. An attacker could then use the malicious GET request to lure victims to perform unsafe actions in the page (ex. phishing).

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2020-9743",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "Experience Manager",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "6.5.5.0"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "6.4.8.1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "6.3.3.8"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "6.2 SP1-CFP20"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-10T17:15:41.377",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/experience-manager/apsb20-56.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/experience-manager/apsb20-56.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code in a parameter value. An attacker could then use the malicious GET request to lure victims to perform unsafe actions in the page (ex. phishing)."
    },
    {
      "lang": "es",
      "value": "AEM versiones 6.5.5.0 (y anteriores), 6.4.8.1 (y anteriores), 6.3.3.8 (y anteriores) y 6.2 SP1-CFP20 (y posteriores), están afectadas por una vulnerabilidad de inyección HTML en el componente content editor que permite a usuarios no autenticados diseñar una petición HTTP que incluya código HTML arbitrario en un valor de parámetro. Un atacante podría utilizar la petición GET maliciosa para atraer a las víctimas a llevar a cabo acciones no seguras en la página (por ejemplo, phishing)"
    }
  ],
  "lastModified": "2026-06-17T03:28:30.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F61E8D62-4FB7-48E0-A750-C3F6EBE5F613",
              "versionEndIncluding": "6.3.3.8",
              "versionStartIncluding": "6.3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0482E99D-21DC-489C-8E0B-707A70A48FC0",
              "versionEndIncluding": "6.4.8.1",
              "versionStartIncluding": "6.4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9D06479-83AE-4F9A-BAE9-7849798F1A30",
              "versionEndIncluding": "6.5.5.0",
              "versionStartIncluding": "6.5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE7DD1A2-EB34-4862-878F-0768D91ED375"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3E28FB2-DD09-471E-A846-45D00A1DEAE7"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1537FAD0-6B8C-440E-ADBE-6E55B5E95545"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80CD82AA-BD51-44ED-843D-155E0253A9EE"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp12.1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F50647B-FD1C-43E4-A688-F9B4ED244028"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A97165F4-F357-4271-A141-4091973F9A34"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92D76A04-0B29-4BF2-B016-7FA82B12FE53"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp15:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C555A79-F619-4119-9DEA-0679059F6111"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp16:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9732E3D9-15A3-4571-8B40-88B7FF64D994"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp17:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2DB2AFF-4C6D-4CFD-8BCD-6ED5FABF677C"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp18:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D72D08D-3B08-4FA9-A5D8-1709229CCAA9"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp19:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CEA0E51-6982-4F18-A7BC-500C341E415E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A531C028-FED4-473E-BB08-E4D92C3AE5F0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp20:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "880D18CA-1FF0-436D-91C0-E29C85C4AD8C"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8871723-95D7-4A4A-A232-A7CE7F5EE020"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C22A756-74DB-4D4F-9B32-00D85F127260"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EBDA638-4C8A-438F-96E2-B5EAA2B21DCF"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A457620-A285-4F7F-8FA7-3F0C514E4658"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BA4E1EE-C90A-4028-8DBC-47F6DF90021E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD076F63-6F46-4852-9080-1AD72B5001F9"
            },
            {
              "criteria": "cpe:2.3:a:adobe:experience_manager:6.2.0.0:sp1-cfp9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D75869C-D57A-480B-941A-8679EABAE593"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}