CVE-2023-48608
Status: ModifiedLow (3.5)—
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vulnerability. A low-privileged attacker could leverage this vulnerability to achieve a low-integrity impact within the application. Exploitation of this issue requires user interaction.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Base score: 3.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.76%
- Percentile among all scored CVEs: 54
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-20
References
Raw JSON (NVD)
Show
{
"id": "CVE-2023-48608",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.5,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "Adobe Experience Manager",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "6.5.18"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2023-12-15T11:15:44.327",
"references": [
{
"url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@adobe.com"
},
{
"url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vulnerability. A low-privileged attacker could leverage this vulnerability to achieve a low-integrity impact within the application. Exploitation of this issue requires user interaction."
},
{
"lang": "es",
"value": "Las versiones 6.5.18 y anteriores de Adobe Experience Manager se ven afectadas por una vulnerabilidad de validación de entrada incorrecta. Un atacante con pocos privilegios podría aprovechar esta vulnerabilidad para lograr un impacto de baja integridad dentro de la aplicación. La explotación de este problema requiere la interacción del usuario."
}
],
"lastModified": "2026-06-17T06:34:36.993",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1184F916-16A4-4066-A7A5-6FAACE9F3679",
"versionEndIncluding": "6.5.18"
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:-:*:*:*:aem_cloud_service:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A88C919F-4221-4669-A725-06094F811012"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}