ZeroHour

CVE-2021-40722

CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.

Vendors
adobe
Products
experience manager, experience manager cloud service
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news