VDB
CVE-2025-54251
CVE-2025-54251
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.
EPSS 9.42% · 93.0th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score
9.42%
93.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| adobe | experience_manager | 0, 6.5, 6.5 |
| Adobe | Adobe Experience Manager | 0, 0 |
Timeline
- Jun 10, 2021 CrowdSec Sighting
- Aug 12, 2021 CrowdSec Sighting
- Mar 29, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
- Dec 16, 2022 CrowdSec Sighting
- Dec 16, 2022 CrowdSec Sighting
- Dec 19, 2022 CrowdSec Sighting
- Dec 24, 2022 CrowdSec Sighting
- Feb 27, 2023 CrowdSec Sighting
- Aug 10, 2023 CrowdSec Sighting