VDB

CVE-2025-54251

CVE-2025-54251 PUBLISHED CVSS 4.300000190734863 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.

EPSS 9.42% · 93.0th percentile

Risk Scores

CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score
9.42%
93.0th percentile

Affected Products

VendorProductVersions
adobeexperience_manager0, 6.5, 6.5
AdobeAdobe Experience Manager0, 0

Timeline

  • Jun 10, 2021 CrowdSec Sighting
  • Aug 12, 2021 CrowdSec Sighting
  • Mar 29, 2022 CrowdSec Sighting
  • Dec 11, 2022 CrowdSec Sighting
  • Dec 11, 2022 CrowdSec Sighting
  • Dec 11, 2022 CrowdSec Sighting
  • Dec 16, 2022 CrowdSec Sighting
  • Dec 16, 2022 CrowdSec Sighting
  • Dec 19, 2022 CrowdSec Sighting
  • Dec 24, 2022 CrowdSec Sighting
  • Feb 27, 2023 CrowdSec Sighting
  • Aug 10, 2023 CrowdSec Sighting
Open in Interactive Console →
$ Console Community · 100/wk Open console ›